CVE-2025-24398

Severity
8.8HIGH
EPSS
0.1%
top 77.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 22

Description

Jenkins Bitbucket Server Integration Plugin 2.1.0 through 4.1.3 (both inclusive) allows attackers to craft URLs that would bypass the CSRF protection of any target URL in Jenkins.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages3 packages

🔴Vulnerability Details

3
GHSA
Bitbucket Server Integration Plugin allows bypassing CSRF protection for any URL2025-01-22
OSV
Bitbucket Server Integration Plugin allows bypassing CSRF protection for any URL2025-01-22
CVEList
CVE-2025-24398: Jenkins Bitbucket Server Integration Plugin 22025-01-22

📋Vendor Advisories

1
Jenkins
Jenkins Security Advisory 2025-01-222025-01-22