Vulnerabilities > Jenkins > Bitbucket Server Integration > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-03-29 CVE-2022-28133 Cross-site Scripting vulnerability in Jenkins Bitbucket Server Integration
Jenkins Bitbucket Server Integration Plugin 3.1.0 and earlier does not limit URL schemes for callback URLs on OAuth consumers, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to create BitBucket Server consumers.
network
low complexity
jenkins CWE-79
5.4
2022-03-29 CVE-2022-28134 Missing Authorization vulnerability in Jenkins Bitbucket Server Integration
Jenkins Bitbucket Server Integration Plugin 3.1.0 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to create, view, and delete BitBucket Server consumers.
network
low complexity
jenkins CWE-862
5.4