Логотип exploitDog
bind:CVE-2023-41937
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-41937

Количество 2

Количество 2

nvd логотип

CVE-2023-41937

больше 2 лет назад

Jenkins Bitbucket Push and Pull Request Plugin 2.4.0 through 2.8.3 (both inclusive) trusts values provided in the webhook payload, including certain URLs, and uses configured Bitbucket credentials to connect to those URLs, allowing attackers to capture Bitbucket credentials stored in Jenkins by sending a crafted webhook payload.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-vrpg-c7c4-8mpx

больше 2 лет назад

SSRF vulnerability in Jenkins Bitbucket Push and Pull Request Plugin allows capturing credentials

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-41937

Jenkins Bitbucket Push and Pull Request Plugin 2.4.0 through 2.8.3 (both inclusive) trusts values provided in the webhook payload, including certain URLs, and uses configured Bitbucket credentials to connect to those URLs, allowing attackers to capture Bitbucket credentials stored in Jenkins by sending a crafted webhook payload.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-vrpg-c7c4-8mpx

SSRF vulnerability in Jenkins Bitbucket Push and Pull Request Plugin allows capturing credentials

CVSS3: 7.5
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу