Vulnerability GHSA-vrpg-c7c4-8mpx
High Risk
HIGH RISK
CVSS Score: 7.5
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
3 years ago
September 06, 2023 at 03:30 PM UTC
SSRF vulnerability in Jenkins Bitbucket Push and Pull Request Plugin allows capturing credentials
2.4.0
2.4.0
Summary
SSRF vulnerability in Jenkins Bitbucket Push and Pull Request Plugin allows capturing credentials
Details
Jenkins Bitbucket Push and Pull Request Plugin 2.4.0 through 2.8.3 (both inclusive) trusts values provided in the webhook payload, including certain URLs, and uses configured Bitbucket credentials to connect to those URLs, allowing attackers to capture Bitbucket credentials stored in Jenkins by sending a crafted webhook payload.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Impacted packages
Timeline
Published
3 years ago
September 06, 2023 at 03:30 PM UTC
Last Modified
2 years ago
February 16, 2024 at 08:13 AM UTC