CVE-2022-28134 – io.jenkins.plugins:atlassian-bitbucket-server-integration
Package
Manager: maven
Name: io.jenkins.plugins:atlassian-bitbucket-server-integration
Vulnerable Version: >=0 <3.2.0
Severity
Level: Medium
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
EPSS: 0.00906 pctl0.74877
Details
Missing permission checks in Jekins Bitbucket Server Integration Plugin Jenkins Bitbucket Server Integration Plugin 3.1.0 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to create, view, and delete BitBucket Server consumers.
Metadata
Created: 2022-03-30T00:00:25Z
Modified: 2022-11-29T21:52:22Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/03/GHSA-r5r6-v8qh-pmpq/GHSA-r5r6-v8qh-pmpq.json
CWE IDs: ["CWE-862"]
Alternative ID: GHSA-r5r6-v8qh-pmpq
Finding: F039
Auto approve: 1