Security Advisory

CVE-2022-43423

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2022-10-19 00:00:00
Last updated 2025-05-08 18:26:26
Assigner jenkins
State PUBLISHED

Description

Jenkins Compuware Source Code Download for Endevor, PDS, and ISPW Plugin 2.0.12 and earlier implements an agent/controller message that does not limit where it can be executed, allowing attackers able to control agent processes to obtain the values of Java system properties from the Jenkins controller process.