Description
Jenkins Compuware Topaz for Total Test Plugin 2.4.8 and earlier implements an agent/controller message that does not limit where it can be executed, allowing attackers able to control agent processes to read arbitrary files on the Jenkins controller file system.
Remediation
References
http://www.openwall.com/lists/oss-security/2022/10/19/3
https://www.jenkins.io/security/advisory/2022-10-19/#SECURITY-2624
Related Vulnerabilities
CVE-2020-7621 Vulnerability in npm package strong-nginx-controller
CVE-2020-8123 Vulnerability in npm package strapi
CVE-2022-35278 Vulnerability in maven package org.apache.activemq:artemis-web
CVE-2021-21290 Vulnerability in maven package io.netty:netty-transport
CVE-2020-11972 Vulnerability in maven package org.apache.camel:camel-rabbitmq