Description
Jenkins Compuware Xpediter Code Coverage Plugin 1.0.7 and earlier implements an agent/controller message that does not limit where it can be executed, allowing attackers able to control agent processes to obtain the values of Java system properties from the Jenkins controller process.
Remediation
References
http://www.openwall.com/lists/oss-security/2022/10/19/3
https://www.jenkins.io/security/advisory/2022-10-19/#SECURITY-2627
Related Vulnerabilities
CVE-2020-36184 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2022-37865 Vulnerability in maven package org.apache.ivy:ivy
CVE-2021-21695 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2020-11971 Vulnerability in maven package org.apache.camel:camel-main
CVE-2019-1003072 Vulnerability in maven package org.jenkins-ci.plugins:wildfly-deployer