Vulnerabilities > Jenkins > Bitbucket Server Integration > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-03-29 | CVE-2022-28133 | Cross-site Scripting vulnerability in Jenkins Bitbucket Server Integration Jenkins Bitbucket Server Integration Plugin 3.1.0 and earlier does not limit URL schemes for callback URLs on OAuth consumers, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to create BitBucket Server consumers. | 5.4 |
2022-03-29 | CVE-2022-28134 | Missing Authorization vulnerability in Jenkins Bitbucket Server Integration Jenkins Bitbucket Server Integration Plugin 3.1.0 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to create, view, and delete BitBucket Server consumers. | 5.4 |