Vulnerability GHSA-vrpg-c7c4-8mpx

High Risk
HIGH RISK
CVSS Score: 7.5
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
3 years ago
September 06, 2023 at 03:30 PM UTC
SSRF vulnerability in Jenkins Bitbucket Push and Pull Request Plugin allows capturing credentials
2.4.0
2.4.0

Summary

SSRF vulnerability in Jenkins Bitbucket Push and Pull Request Plugin allows capturing credentials

Details

Jenkins Bitbucket Push and Pull Request Plugin 2.4.0 through 2.8.3 (both inclusive) trusts values provided in the webhook payload, including certain URLs, and uses configured Bitbucket credentials to connect to those URLs, allowing attackers to capture Bitbucket credentials stored in Jenkins by sending a crafted webhook payload.

Timeline

Published
3 years ago
September 06, 2023 at 03:30 PM UTC
Last Modified
2 years ago
February 16, 2024 at 08:13 AM UTC