Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-41937


Jenkins Bitbucket Push and Pull Request Plugin 2.4.0 through 2.8.3 (both inclusive) trusts values provided in the webhook payload, including certain URLs, and uses configured Bitbucket credentials to connect to those URLs, allowing attackers to capture Bitbucket credentials stored in Jenkins by sending a crafted webhook payload.


Published

2023-09-06T13:15:10.593

Last Modified

2024-11-21T08:21:57.420

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Primary
    CWE-918

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application jenkins bitbucket_push_and_pull_request ≤ 2.8.3 Yes

References