Bug 2044466 (CVE-2022-20618) - CVE-2022-20618 jenkins-2-plugins/cloudbees-bitbucket-branch-source: missing permission check allow ID enumeration
Summary: CVE-2022-20618 jenkins-2-plugins/cloudbees-bitbucket-branch-source: missing p...
Keywords:
Status: NEW
Alias: CVE-2022-20618
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Nobody
QA Contact:
URL:
Whiteboard:
Depends On: 2044952 2047839
Blocks: 2044461
TreeView+ depends on / blocked
 
Reported: 2022-01-24 16:53 UTC by Michael Kaplan
Modified: 2024-05-02 18:49 UTC (History)
10 users (show)

Fixed In Version: cloudbees-bitbucket-branch-source 746.v350d2781c184
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Michael Kaplan 2022-01-24 16:53:11 UTC
A missing permission check in Jenkins Bitbucket Branch Source Plugin 737.vdf9dc06105be and earlier allows attackers with Overall/Read access to enumerate credentials IDs of credentials stored in Jenkins.

Reference:

https://www.jenkins.io/security/advisory/2022-01-12/#SECURITY-2033

Comment 2 Adam Kaplan 2022-01-26 21:04:23 UTC
There are a few layers of transitive dependencies here which need to be updated:

- blueocean depends on blueocean-bitbucket-pipeline:1.24.8
- blueocean-bitbucket-pipeline depends on ... cloudbees-bitbucket-branch-source:2.4.4

Ideally blueocean cuts a new parent plugin and we can just pull the fix in.


Note You need to log in before you can comment on or make changes to this bug.