cbcvebase.
CVE-2023-41937
published 2023-09-06

CVE-2023-41937: Jenkins Bitbucket Push and Pull Request Plugin 2.4.0 through 2.8.3 (both inclusive) trusts values provided in the webhook payload, including certain URLs, and…

PriorityP343high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.57%
43.2th percentile
Jenkins Bitbucket Push and Pull Request Plugin 2.4.0 through 2.8.3 (both inclusive) trusts values provided in the webhook payload, including certain URLs, and uses configured Bitbucket credentials to connect to those URLs, allowing attackers to capture Bitbucket credentials stored in Jenkins by sending a crafted webhook payload.

Affected

17 ranges
VendorProductVersion rangeFixed in
jenkinsassembla_auth_plugin
jenkinsaws_codecommit_trigger_plugin
jenkinsbitbucket_push_and_pull_request2.4.0 – 2.8.3
jenkinsbitbucket_push_and_pull_request_plugin
jenkinsconfig_file_provider_plugin
jenkinsdisabled_permissions_can_be_granted_by_ssh2_easy_plugin
jenkinsdisabled_permissions_granted_by_assembla_auth_plugin
jenkinsfrugal_testing_plugin
jenkinsgoogle_login_plugin
jenkinsivy_plugin
jenkinsjob_configuration_history_plugin
jenkinsnon-constant_time_token_comparison_in_google_login_plugin
jenkinspipeline_maven_integration_plugin
jenkinsqualys_container_scanning_connector_plugin
jenkinsssh2_easy_plugin
jenkinstap_plugin
jenkins_projectjenkins_bitbucket_push_and_pull_request_plugin2.4.0 – 2.8.3
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.