Known vulnerabilities in Bitbucket Branch Source
Vendor:
Jenkins
Software:
Bitbucket Branch Source
Software CPE:
cpe:2.3:a:jenkins:bitbucket_branch_source:*:*:*:*:*:*:*:*
Website:
https://jenkins.io/
Total vulnerabilities:
4
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
5.3
Breakdown by Severity Chart
887.va_d359b_3d2d8d
886.v44cf5e4ecec5
871.v28d74e8b_4226
866.vdea_7dcd3008e
746.v350d2781c184
737.vdf9dc06105be
2.9.12
2.9.11.2
2.9.11
2.9.10
2.9.9
2.9.8
2.9.7.2
2.9.7
2.9.6
2.9.5
2.9.4
2.9.3
2.9.2
2.9.1
2.9.0
2.8.0
2.7.0
2.6.0
2.5.0
2.4.6
2.4.5
2.4.4
2.4.3
2.4.2
2.4.1
2.4.0
2.3.0
2.2.16
2.2.15
2.2.14
2.2.13
2.2.12
2.2.11
2.2.10
2.2.9
2.2.8
2.2.7
2.2.6
2.2.5
2.2.4
2.2.3
2.2.2
2.2.1
2.2.0
2.1.2
2.1.1
2.1.0
2.0.2
2.0.1
2.0.0
1.9
1.8
1.7
1.6
1.5
1.4
1.3
Vulnerabilities (4)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU93505 - Exposure of sensitive information to an unauthorized actor CVE-2024-39460 |
CWE-200 | Low | 887.va_d359b_3d2d8d | 01.07.2024 |
SB2024070121 |
||
| #VU87289 - Improper Access Control CVE-2024-28152 |
CWE-284 | Medium | 871.v28d74e8b_4226 | 08.03.2024 |
SB2024030817 |
||
| #VU59585 - Cross-Site Request Forgery (CSRF) CVE-2022-20619 |
CWE-352 | Low | 746.v350d2781c184 | 13.01.2022 |
SB2022011312 |
||
| #VU59584 - Permissions, Privileges, and Access Controls CVE-2022-20618 |
CWE-264 | Low | 746.v350d2781c184 | 13.01.2022 |
SB2022011312 |