CVE-2023-41937

HIGH

Jenkins Bitbucket Push and Pull Request Plugin 2.4.0-2.8.3 - Server-Side Request Forgery via Webhook Payload

Title source: llm
STIX 2.1

Description

Jenkins Bitbucket Push and Pull Request Plugin 2.4.0 through 2.8.3 (both inclusive) trusts values provided in the webhook payload, including certain URLs, and uses configured Bitbucket credentials to connect to those URLs, allowing attackers to capture Bitbucket credentials stored in Jenkins by sending a crafted webhook payload.

References (2)

Core 2
Core References
Mailing List, Third Party Advisory
http://www.openwall.com/lists/oss-security/2023/09/06/9

Scores

CVSS v3 7.5
EPSS 0.0007
EPSS Percentile 21.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-918
Status published
Products (2)
io.jenkins.plugins/bitbucket-push-and-pull-request 2.4.0 - 2.8.4Maven
jenkins/bitbucket_push_and_pull_request 2.4.0 - 2.8.3
Published Sep 06, 2023
Tracked Since Feb 18, 2026