org.jenkins-ci.plugins:cloudbees-bitbucket-branch-source
Maven4 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.jenkins-ci.plugins:cloudbees-bitbucket-branch-sourcepage 1 of 1
- CVE-2022-20618MEDIUMCVSS 4.3EG 4.3✓ Fixed in 2.9.7.22022-01-12
vulnerable: 1.3 ... 2.9.7 (55 versions)
A missing permission check in Jenkins Bitbucket Branch Source Plugin 737.vdf9dc06105be and earlier allows attackers with Overall/Read access to enumerate credentials IDs of credentials stored in Jenkins.
- CVE-2022-20619HIGHCVSS 7.1EG 7.1✓ Fixed in 2.9.7.22022-01-12
vulnerable: 1.3 ... 2.9.7 (55 versions)
A cross-site request forgery (CSRF) vulnerability in Jenkins Bitbucket Branch Source Plugin 737.vdf9dc06105be and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through an…
- CVE-2024-28152MEDIUMCVSS 6.3EG 6.3✓ Fixed in 871.v28d74e8b_42262024-03-06
vulnerable: 1.3 ... 866.vdea_7dcd3008e (92 versions)
In Jenkins Bitbucket Branch Source Plugin 866.vdea_7dcd3008e and earlier, except 848.850.v6a_a_2a_234a_c81, when discovering pull requests from forks, the trust policy "Forks in the same account" allows changes to Jenkinsfiles from users w…
- CVE-2024-39460MEDIUMCVSS 4.3EG 4.3✓ Fixed in 887.va2024-06-26
vulnerable: 1.3 ... 886.v44cf5e4ecec5 (102 versions)
Jenkins Bitbucket Branch Source Plugin 886.v44cf5e4ecec5 and earlier prints the Bitbucket OAuth access token as part of the Bitbucket URL in the build log in some cases.
Check whether org.jenkins-ci.plugins:cloudbees-bitbucket-branch-source is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.jenkins-ci.plugins:cloudbees-bitbucket-branch-source CVEs against the assets you own.
Start Free Scan →