-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from the RemoteSystemProperties class implementing a Jenkins remoting Callable without proper execution context restrictions. The pre-patch version used hudson.remoting.Callable with an empty checkRoles() implementation, failing to prevent agents from submitting this operation to controllers. The fix in 1.0.4 changed the inheritance to MasterToSlaveCallable which enforces controller-to-agent execution only. The call() method that retrieves system properties becomes dangerous when executed in the wrong context, which is exactly what the vulnerability describes.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| com.compuware.jenkins:compuware-zadviser-api | maven | <= 1.0.3 | 1.0.4 |
KEV Misses 88% of Exploited CVEs- Get the report