logo

CVE-2022-28134 io.jenkins.plugins:atlassian-bitbucket-server-integration

Package

Manager: maven
Name: io.jenkins.plugins:atlassian-bitbucket-server-integration
Vulnerable Version: >=0 <3.2.0

Severity

Level: Medium

CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

EPSS: 0.00906 pctl0.74877

Details

Missing permission checks in Jekins Bitbucket Server Integration Plugin Jenkins Bitbucket Server Integration Plugin 3.1.0 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to create, view, and delete BitBucket Server consumers.

Metadata

Created: 2022-03-30T00:00:25Z
Modified: 2022-11-29T21:52:22Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/03/GHSA-r5r6-v8qh-pmpq/GHSA-r5r6-v8qh-pmpq.json
CWE IDs: ["CWE-862"]
Alternative ID: GHSA-r5r6-v8qh-pmpq
Finding: F039
Auto approve: 1