First published: Tue Mar 29 2022(Updated: )
Jenkins Bitbucket Server Integration Plugin 3.1.0 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to create, view, and delete BitBucket Server consumers.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Bitbucket Server Integration Plugin | <=3.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-28134 is classified as a medium-severity vulnerability.
To fix CVE-2022-28134, upgrade the Jenkins Bitbucket Server Integration Plugin to version 3.1.1 or later.
CVE-2022-28134 affects users of Jenkins Bitbucket Server Integration Plugin version 3.1.0 and earlier.
The consequences of CVE-2022-28134 include unauthorized access allowing attackers to create, view, and delete BitBucket Server consumers.
CVE-2022-28134 describes several HTTP endpoints that lack permission checks, leading to security concerns.