Description
Jenkins Compuware Topaz for Total Test Plugin 2.4.8 and earlier implements an agent/controller message that does not limit where it can be executed, allowing attackers able to control agent processes to read arbitrary files on the Jenkins controller file system.
Remediation
References
http://www.openwall.com/lists/oss-security/2022/10/19/3
https://www.jenkins.io/security/advisory/2022-10-19/#SECURITY-2624
Related Vulnerabilities
CVE-2020-7787 Vulnerability in npm package react-adal
CVE-2019-1003065 Vulnerability in maven package org.jenkins-ci.plugins:cloudshare-docker
CVE-2019-1003093 Vulnerability in maven package org.jenkins-ci.plugins:nomad
CVE-2023-46497 Vulnerability in npm package @evershop/evershop
CVE-2023-37895 Vulnerability in maven package org.apache.jackrabbit:jackrabbit-standalone