CVE-2023-41937
Expert Analysis
Professional remediation guidance
Get tailored security recommendations from our analyst team for CVE-2023-41937. We'll provide specific mitigation strategies based on your environment and risk profile.
Description
Jenkins Bitbucket Push and Pull Request Plugin 2.4.0 through 2.8.3 (both inclusive) trusts values provided in the webhook payload, including certain URLs, and uses configured Bitbucket credentials to connect to those URLs, allowing attackers to capture Bitbucket credentials stored in Jenkins by sending a crafted webhook payload.
Available Exploits
Related News
Affected Products
Affected Versions:
GitHub Security Advisories
Community-driven vulnerability intelligence from GitHub
SSRF vulnerability in Jenkins Bitbucket Push and Pull Request Plugin allows capturing credentials
GHSA-vrpg-c7c4-8mpxAdvisory Details
Affected Packages
CVSS Scoring
CVSS Score
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
References
Advisory provided by GitHub Security Advisory Database. Published: September 6, 2023, Modified: January 30, 2024