Jenkins Compuware zAdviser API Plugin 1.0.3 and earlier does not restrict execution of a controller/agent message to agents, allowing attackers able to control agent processes to retrieve Java system properties.
2022-07-27T15:15:09.777
2024-11-21T07:14:02.023
Modified
CVSSv3.1: 8.2 (HIGH)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | jenkins | compuware_zadviser_api | ≤ 1.0.3 | Yes |
| Application | jenkins | jenkins | ≤ 2.303.2 | No |
| Application | jenkins | jenkins | ≤ 2.318 | No |