cbcvebase.
CVE-2025-24398
published 2025-01-22

CVE-2025-24398: Jenkins Bitbucket Server Integration Plugin 2.1.0 through 4.1.3 (both inclusive) allows attackers to craft URLs that would bypass the CSRF protection of any…

PriorityP343high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.29%
20.4th percentile
Jenkins Bitbucket Server Integration Plugin 2.1.0 through 4.1.3 (both inclusive) allows attackers to craft URLs that would bypass the CSRF protection of any target URL in Jenkins.

Affected

11 ranges
VendorProductVersion rangeFixed in
jenkinsazure_service_fabric_plugin
jenkinsbitbucket_server_integration>= 2.1.0 < 4.1.44.1.4
jenkinsbitbucket_server_integration_plugin
jenkinscache_confusion_in_eiffel_broadcaster_plugin
jenkinseiffel_broadcaster_plugin
jenkinsfolder-based_authorization_strategy_plugin
jenkinsgitlab_plugin
jenkinsopenid_connect_authentication_plugin
jenkinstokens_displayed_without_masking_by_zoom_plugin
jenkinszoom_plugin
jenkins_projectjenkins_bitbucket_server_integration_plugin2.1.0 – 4.1.3
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.