A missing permission check in Jenkins Bitbucket Branch Source Plugin 737.vdf9dc06105be and earlier allows attackers with Overall/Read access to enumerate credentials IDs of credentials stored in Jenkins. Reference: https://www.jenkins.io/security/advisory/2022-01-12/#SECURITY-2033
There are a few layers of transitive dependencies here which need to be updated: - blueocean depends on blueocean-bitbucket-pipeline:1.24.8 - blueocean-bitbucket-pipeline depends on ... cloudbees-bitbucket-branch-source:2.4.4 Ideally blueocean cuts a new parent plugin and we can just pull the fix in.