{"id":"GHSA-w4jv-6rg4-pr4m","summary":"Cross-Site Request Forgery in Jenkins Bitbucket Branch Source Plugin","details":"Jenkins Bitbucket Branch Source Plugin prior to 746.v350d2781c184, 725.vd9f8be0fa250, 2.9.11.2, and 2.9.7.2 does not require POST requests for an HTTP endpoint, resulting in a cross-site request forgery (CSRF) vulnerability.\n\nThis allows attackers with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.\n\nBitbucket Branch Source Plugin 746.v350d2781c184, 725.vd9f8be0fa250, 2.9.11.2, and 2.9.7.2 requires POST requests for the affected HTTP endpoint.","aliases":["CVE-2022-20619"],"modified":"2024-02-16T08:08:58.837641Z","published":"2022-01-13T00:01:00Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2022-06-20T22:49:06Z","nvd_published_at":"2022-01-12T20:15:00Z","cwe_ids":["CWE-352"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-20619"},{"type":"WEB","url":"https://github.com/jenkinsci/bitbucket-branch-source-plugin/commit/a596f651a4b3bfe31a087c4d392e81c0167ab551"},{"type":"WEB","url":"https://github.com/CVEProject/cvelist/blob/2d78eb36f4d084db7fb35f1535d8d84fdcb7d859/2022/20xxx/CVE-2022-20619.json"},{"type":"PACKAGE","url":"https://github.com/jenkinsci/bitbucket-branch-source-plugin"},{"type":"WEB","url":"https://www.jenkins.io/security/advisory/2022-01-12/#SECURITY-2467"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2022/01/12/6"}],"affected":[{"package":{"name":"org.jenkins-ci.plugins:cloudbees-bitbucket-branch-source","ecosystem":"Maven","purl":"pkg:maven/org.jenkins-ci.plugins/cloudbees-bitbucket-branch-source"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"726.v7e6f53de133c"},{"fixed":"746.v350d2781c184"}]}],"versions":["726.vb0c1ea6c9336","731.v1f980b7eba32","734.v2f848c5e6ea2","737.vdf9dc06105be"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/01/GHSA-w4jv-6rg4-pr4m/GHSA-w4jv-6rg4-pr4m.json"}},{"package":{"name":"org.jenkins-ci.plugins:cloudbees-bitbucket-branch-source","ecosystem":"Maven","purl":"pkg:maven/org.jenkins-ci.plugins/cloudbees-bitbucket-branch-source"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"720.vbe985dd73d66"},{"fixed":"725.vd9f8be0fa250"}]}],"versions":["723.vbabdf19eb4c7"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/01/GHSA-w4jv-6rg4-pr4m/GHSA-w4jv-6rg4-pr4m.json"}},{"package":{"name":"org.jenkins-ci.plugins:cloudbees-bitbucket-branch-source","ecosystem":"Maven","purl":"pkg:maven/org.jenkins-ci.plugins/cloudbees-bitbucket-branch-source"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.9.8"},{"fixed":"2.9.11.2"}]}],"versions":["2.9.10","2.9.11","2.9.8","2.9.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/01/GHSA-w4jv-6rg4-pr4m/GHSA-w4jv-6rg4-pr4m.json"}},{"package":{"name":"org.jenkins-ci.plugins:cloudbees-bitbucket-branch-source","ecosystem":"Maven","purl":"pkg:maven/org.jenkins-ci.plugins/cloudbees-bitbucket-branch-source"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.9.7.2"}]}],"versions":["1.3","1.4","1.5","1.7","1.8","1.9","2.0.0","2.0.0-beta-1","2.0.1","2.0.2","2.0.2-beta-1","2.1.0","2.1.1","2.1.1-beta-1","2.1.2","2.2.0","2.2.0-alpha-1","2.2.0-alpha-4","2.2.0-beta-1","2.2.1","2.2.10","2.2.11","2.2.12","2.2.13","2.2.14","2.2.15","2.2.16","2.2.2","2.2.3","2.2.4","2.2.5","2.2.6","2.2.7","2.2.8","2.2.9","2.3.0","2.4.0","2.4.1","2.4.2","2.4.3","2.4.4","2.4.5","2.4.6","2.5.0","2.6.0","2.7.0","2.8.0","2.9.0","2.9.1","2.9.2","2.9.3","2.9.4","2.9.5","2.9.6","2.9.7"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/01/GHSA-w4jv-6rg4-pr4m/GHSA-w4jv-6rg4-pr4m.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N"}]}