Permission Check Flaw in Jenkins Bitbucket Branch Source Plugin by Jenkins
CVE-2022-20618

4.3MEDIUM

Key Information:

Vendor
Jenkins
Vendor
CVE Published:
12 January 2022

Summary

A security issue exists in the Jenkins Bitbucket Branch Source Plugin where a missing permission check allows attackers with Overall/Read access to enumerate the IDs of credentials stored within Jenkins. This vulnerability can lead to unauthorized access to sensitive credential information, increasing the risk for organizations utilizing this plugin. It is crucial for users of affected versions to apply the necessary security patches to mitigate potential exposure.

Affected Version(s)

Jenkins Bitbucket Branch Source Plugin <= 737.vdf9dc06105be

Jenkins Bitbucket Branch Source Plugin 725.vd9f8be0fa250

Jenkins Bitbucket Branch Source Plugin 2.9.11.2

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.