PT-2025-44299 · Jenkins · Jenkins Publish To Bitbucket Plugin+1

Published

2025-10-29

·

Updated

2025-10-30

·

CVE-2025-64150

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Publish to Bitbucket Plugin versions 0.4 and earlier
Description A flaw exists where a missing permission check allows attackers possessing Overall/Read permission to establish a connection to a URL specified by the attacker, utilizing credentials IDs obtained through separate means. This can lead to the capture of credentials stored within Jenkins.
Recommendations Update Jenkins Publish to Bitbucket Plugin to a version later than 0.4.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-64150
GHSA-WPR5-RC2J-99P2

Affected Products

Jenkins
Jenkins Publish To Bitbucket Plugin