CVE-2025-24398

Jenkins Bitbucket Server Integration Plugin 2.1.0 through 4.1.3 (both inclusive) allows attackers to craft URLs that would bypass the CSRF protection of any target URL in Jenkins.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

cpe:2.3:a:jenkins:bitbucket_server_integration:*:*:*:*:*:jenkins:*:*

History

06 Jun 2025, 15:23

Type Values Removed Values Added
CPE cpe:2.3:a:jenkins:bitbucket_server_integration:*:*:*:*:*:jenkins:*:*
References () https://www.jenkins.io/security/advisory/2025-01-22/#SECURITY-3434 - () https://www.jenkins.io/security/advisory/2025-01-22/#SECURITY-3434 - Vendor Advisory
First Time Jenkins
Jenkins bitbucket Server Integration

22 Jan 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-22 17:15

Updated : 2025-06-06 15:23


NVD link : CVE-2025-24398

Mitre link : CVE-2025-24398


JSON object : View

Products Affected

jenkins

  • bitbucket_server_integration
CWE

No CWE.