Total
2 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2022-28134 | 1 Jenkins | 1 Bitbucket Server Integration | 2022-04-04 | 5.5 MEDIUM | 5.4 MEDIUM |
Jenkins Bitbucket Server Integration Plugin 3.1.0 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to create, view, and delete BitBucket Server consumers. | |||||
CVE-2022-28133 | 1 Jenkins | 1 Bitbucket Server Integration | 2022-04-04 | 3.5 LOW | 5.4 MEDIUM |
Jenkins Bitbucket Server Integration Plugin 3.1.0 and earlier does not limit URL schemes for callback URLs on OAuth consumers, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to create BitBucket Server consumers. |