Database/Control plane, storage & DevOps
Jenkins Bitbucket Push and Pull Request Plugin: webhook payload can redirect credentialed requests
Impact
The plugin trusts URLs supplied in the incoming webhook payload and connects to them using the Bitbucket credentials stored in Jenkins, so a crafted webhook makes the controller send those credentials to an attacker-chosen endpoint. No Jenkins account is needed - only the ability to reach the webhook endpoint, which is usually exposed for the SCM to call. Stolen SCM credentials give write access to the repositories that define the cluster's build and deploy pipelines. Affects version 4.0.1 and earlier.
Who can reach it
Unauthenticated, anyone who can POST to the plugin's webhook endpoint on the Jenkins controller. If that endpoint is internet-facing for Bitbucket Cloud, exposure is external.
What to do
Update the Bitbucket Push and Pull Request Plugin past 4.0.1 per the Jenkins advisory and restart the controller. Treat the stored Bitbucket credentials as potentially exposed and rotate them; restricting the webhook endpoint to Bitbucket source ranges limits who can trigger it in the meantime.
References
Related entries
- Ceph (Python bindings, IMAP4_SSL/SMTP_SSL TLS clients): Ceph's Python code constructs imaplib.IMAP4_SSL andNCVD-2024-010-ceph-python-bindings-imap4-ssl-s · Ceph (Python bindings, IMAP4_SSL/SMTP_SSL TLS clients)Medium
- rclone (serve s3): Path traversal in rclone's S3 gateway lets a caller read and overwrite files above the served root.NCVD-2026-042-rclone-serve-s3 · rclone (serve s3)Medium
- KubeEdge CloudHub (viaduct packer, pkg/viaduct/pkg/packer): ONE COMPROMISED EDGE NODE TAKES DOWN CLOUD-EDGENCVD-2026-053-kubeedge-cloudhub-viaduct-packer · KubeEdge CloudHub (viaduct packer, pkg/viaduct/pkg/packer)Medium
- GitLab CE/EE: pipeline creation race lets a developer act in the context of another user's merge request commitCVE-2024-11222 · GitLab CE/EE (pipeline creation race condition)Medium
- Ansible Automation Platform images: group-writable /etc/passwd lets a container user become root in-containerCVE-2025-57847 · Red Hat Ansible Automation Platform container images (/etc/passwd permissions)Medium
- galaxy_ng: namespace avatar URL is fetched unchecked, giving SSRF into internal and metadata endpointsCVE-2026-79717 · galaxy_ng (Ansible Galaxy / Automation Hub server, namespace avatar fetch worker)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.