CVE-2022-28133: XSS
Published Mar 29, 2022
·Updated
Jenkins Bitbucket Server Integration Plugin 3.1.0 and earlier does not limit URL schemes for callback URLs on OAuth consumers, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to create BitBucket Server consumers.
Affected Software
3 affected componentsFixes available
maven/io.jenkins.plugins:atlassian-bitbucket-server-integration>=2.0.0<3.2.0
3.2.0
Jenkins Bitbucket Server Integration Wordpress<=3.1.0
Jenkins Bitbucket Server Integration Jenkins<=3.1.0
Event History
Mar 29, 2022
CVE Published
via MITRE·12:30 PM
Data Sourced
via MITRE·12:30 PM
Description
Mar 30, 2022
Advisory Published
12:00 AM
Frequently Asked Questions
1
What is the severity of CVE-2022-28133?
CVE-2022-28133 is classified as a medium severity stored cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2022-28133?
To fix CVE-2022-28133, upgrade to version 3.2.0 or later of the Jenkins Bitbucket Server Integration Plugin.
3
What versions of Jenkins Bitbucket Server Integration Plugin are affected by CVE-2022-28133?
CVE-2022-28133 affects Jenkins Bitbucket Server Integration Plugin versions 3.1.0 and earlier.
4
What type of vulnerability is CVE-2022-28133?
CVE-2022-28133 is a stored cross-site scripting (XSS) vulnerability.
5
Who can exploit CVE-2022-28133?
CVE-2022-28133 can be exploited by attackers who are able to create Bitbucket Server consumers.