Fiche vulnérabilité
CVE-2022-43430 : faille élevée jenkins compuware topaz for total test (CVSS 7.5)
Description
Jenkins Compuware Topaz for Total Test Plugin 2.4.8 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
En bref
- Sévérité
- Élevée (CVSS 7.5)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Exploitation active
- Non signalée par la CISA
- Publication
- 19 oct. 2022
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- jenkins compuware topaz for total test