Jenkins Bitbucket Server Integration Plugin 2.1.0 through 4.1.3 (both inclusive) allows attackers to craft URLs that would bypass the CSRF protection of any target URL in Jenkins.
CVSS
No CVSS.
References
| Link | Resource |
|---|---|
| https://www.jenkins.io/security/advisory/2025-01-22/#SECURITY-3434 | Vendor Advisory |
Configurations
History
06 Jun 2025, 15:23
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Jenkins
Jenkins bitbucket Server Integration |
|
| CPE | cpe:2.3:a:jenkins:bitbucket_server_integration:*:*:*:*:*:jenkins:*:* | |
| References | () https://www.jenkins.io/security/advisory/2025-01-22/#SECURITY-3434 - Vendor Advisory |
22 Jan 2025, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-01-22 17:15
Updated : 2025-06-06 15:23
NVD link : CVE-2025-24398
Mitre link : CVE-2025-24398
JSON object : View
Products Affected
jenkins
- bitbucket_server_integration
CWE
No CWE.
