CVE-2022-20619
published 2022-01-12CVE-2022-20619: A cross-site request forgery (CSRF) vulnerability in Jenkins Bitbucket Branch Source Plugin 737.vdf9dc06105be and earlier allows attackers to connect to an…
high7.1CVSS 3.1
AVNACLPRNUIRSUCHILAN
A cross-site request forgery (CSRF) vulnerability in Jenkins Bitbucket Branch Source Plugin 737.vdf9dc06105be and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | active_directory_plugin | — | — |
| jenkins | badge_plugin | — | — |
| jenkins | bitbucket_branch_source | <= 2.9.10 | — |
| jenkins | bitbucket_branch_source | — | — |
| jenkins | bitbucket_branch_source_plugin | — | — |
| jenkins | configuration_as_code_plugin | — | — |
| jenkins | conjur_secrets_plugin | — | — |
| jenkins | credentials_binding_plugin | — | — |
| jenkins | credentials_plugin | — | — |
| jenkins | debian_package_builder_plugin | — | — |
| jenkins | docker_commons_plugin | — | — |
| jenkins | groovy_plugin | — | — |
| jenkins | hashicorp_vault_plugin | — | — |
| jenkins | ids_in_bitbucket_branch_source_plugin | — | — |
| jenkins | improper_credentials_masking_in_hashicorp_vault_plugin | — | — |
| jenkins | jenkins_core | — | — |
| jenkins | jenkins_lts | — | — |
| jenkins | jenkins_ui_requesting_they_update_the_plugin | — | — |
| jenkins | jenkins_weekly | — | — |
| jenkins | mailer_plugin | — | — |
| jenkins | matrix_project_plugin | — | — |
| jenkins | metrics_plugin | — | — |
| jenkins | publish_over_ssh_plugin | — | — |
| jenkins | ssh_agent_plugin | — | — |
| jenkins | warnings_plugin | — | — |