Jenkins Compuware Topaz for Total Test Plugin 2.4.8 and earlier implements an agent/controller message that does not limit where it can be executed, allowing attackers able to control agent processes to read arbitrary files on the Jenkins controller file system.
2022-10-19T16:15:11.730
2025-05-08T19:15:55.653
Modified
CVSSv3.1: 7.5 (HIGH)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | jenkins | compuware_topaz_for_total_test | ≤ 2.4.8 | Yes |
| Application | jenkins | jenkins | ≤ 2.303.2 | No |
| Application | jenkins | jenkins | ≤ 2.318 | No |