Vulnerability Description
Jenkins Bitbucket Server Integration Plugin 2.1.0 through 4.1.3 (both inclusive) allows attackers to craft URLs that would bypass the CSRF protection of any target URL in Jenkins.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Jenkins | Bitbucket Server Integration | >= 2.1.0, < 4.1.4 |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2025-24398?
CVE-2025-24398 is a vulnerability with a CVSS score of 8.8 (HIGH). Jenkins Bitbucket Server Integration Plugin 2.1.0 through 4.1.3 (both inclusive) allows attackers to craft URLs that would bypass the CSRF protection of any target URL in Jenkins.
How severe is CVE-2025-24398?
CVE-2025-24398 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-24398?
Check the references section above for vendor advisories and patch information. Affected products include: Jenkins Bitbucket Server Integration.