GHSA-7fvj-g3wp-29g8
GitHub Security Advisory
Jenkins Compuware Topaz for Total Test Plugin vulnerable to Protection Mechanism Failure
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
Jenkins Compuware Topaz for Total Test Plugin 2.4.8 and earlier implements an agent/controller message that does not limit where it can be executed, allowing attackers able to control agent processes to read arbitrary files on the Jenkins controller file system.
Affected Packages
Maven
com.compuware.jenkins:compuware-topaz-for-total-test
Affected versions:
0
(last affected: 2.4.8)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: August 25, 2025 6:33 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.