Description
Jenkins Compuware Xpediter Code Coverage Plugin 1.0.7 and earlier implements an agent/controller message that does not limit where it can be executed, allowing attackers able to control agent processes to obtain the values of Java system properties from the Jenkins controller process.
Remediation
References
https://www.jenkins.io/security/advisory/2022-10-19/#SECURITY-2627
http://www.openwall.com/lists/oss-security/2022/10/19/3
Related Vulnerabilities
CVE-2023-33937 Vulnerability in maven package com.liferay:com.liferay.dynamic.data.mapping.form.web
CVE-2021-25640 Vulnerability in maven package org.apache.dubbo:dubbo
CVE-2022-31170 Vulnerability in maven package org.webjars.npm:openzeppelin__contracts
CVE-2022-34205 Vulnerability in maven package org.jenkins-ci.plugins:jianliao
CVE-2021-32854 Vulnerability in maven package org.webjars.npm:textangular