Description
Jenkins Bitbucket Server Integration Plugin 3.1.0 and earlier does not limit URL schemes for callback URLs on OAuth consumers, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to create BitBucket Server consumers.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-45v7-65q8-x294 | Stored XSS vulnerability in Jenkins Bitbucket Server Integration Plugin |
References
History
No history.
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2024-08-03T05:48:36.605Z
Reserved: 2022-03-29T00:00:00.000Z
Link: CVE-2022-28133
No data.
Status : Modified
Published: 2022-03-29T13:15:08.030
Modified: 2024-11-21T06:56:48.930
Link: CVE-2022-28133
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA