CVE-2022-20618
published 2022-01-12CVE-2022-20618: A missing permission check in Jenkins Bitbucket Branch Source Plugin 737.vdf9dc06105be and earlier allows attackers with Overall/Read access to enumerate…
medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
A missing permission check in Jenkins Bitbucket Branch Source Plugin 737.vdf9dc06105be and earlier allows attackers with Overall/Read access to enumerate credentials IDs of credentials stored in Jenkins.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | active_directory_plugin | — | — |
| jenkins | badge_plugin | — | — |
| jenkins | bitbucket_branch_source | <= 2.9.10 | — |
| jenkins | bitbucket_branch_source | — | — |
| jenkins | bitbucket_branch_source_plugin | — | — |
| jenkins | configuration_as_code_plugin | — | — |
| jenkins | conjur_secrets_plugin | — | — |
| jenkins | credentials_binding_plugin | — | — |
| jenkins | credentials_plugin | — | — |
| jenkins | debian_package_builder_plugin | — | — |
| jenkins | docker_commons_plugin | — | — |
| jenkins | groovy_plugin | — | — |
| jenkins | hashicorp_vault_plugin | — | — |
| jenkins | ids_in_bitbucket_branch_source_plugin | — | — |
| jenkins | improper_credentials_masking_in_hashicorp_vault_plugin | — | — |
| jenkins | jenkins_core | — | — |
| jenkins | jenkins_lts | — | — |
| jenkins | jenkins_ui_requesting_they_update_the_plugin | — | — |
| jenkins | jenkins_weekly | — | — |
| jenkins | mailer_plugin | — | — |
| jenkins | matrix_project_plugin | — | — |
| jenkins | metrics_plugin | — | — |
| jenkins | publish_over_ssh_plugin | — | — |
| jenkins | ssh_agent_plugin | — | — |
| jenkins | warnings_plugin | — | — |