CVE-2022-28134: Medium severity jenkins bitbucket oauth vulnerability
Published Mar 29, 2022
·Updated
Jenkins Bitbucket Server Integration Plugin 3.1.0 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to create, view, and delete BitBucket Server consumers.
Affected Software
1 affected component
Jenkins Bitbucket Server Integration Jenkins<=3.1.0
Event History
Mar 29, 2022
CVE Published
via MITRE·12:30 PM
Data Sourced
via MITRE·12:30 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-28134?
CVE-2022-28134 is classified as a medium-severity vulnerability.
2
How do I fix CVE-2022-28134?
To fix CVE-2022-28134, upgrade the Jenkins Bitbucket Server Integration Plugin to version 3.1.1 or later.
3
Who is affected by CVE-2022-28134?
CVE-2022-28134 affects users of Jenkins Bitbucket Server Integration Plugin version 3.1.0 and earlier.
4
What are the consequences of CVE-2022-28134?
The consequences of CVE-2022-28134 include unauthorized access allowing attackers to create, view, and delete BitBucket Server consumers.
5
What HTTP endpoints are vulnerable in CVE-2022-28134?
CVE-2022-28134 describes several HTTP endpoints that lack permission checks, leading to security concerns.