CVE-2024-28152: Jenkins Bitbucket Branch Source

Medium severity, CVSS 6.3. EPSS: 0.6% chance of exploitation in the next 30 days.

In Jenkins Bitbucket Branch Source Plugin 866.vdea_7dcd3008e and earlier, except 848.850.v6a_a_2a_234a_c81, when discovering pull requests from forks, the trust policy "Forks in the same account" allows changes to Jenkinsfiles from users without write access to the project when using Bitbucket Server.

Affected products

  • Jenkins Bitbucket Branch Source: before 848.850.v6a_a_2a_234a_c81 (fixed in 848.850.v6a_a_2a_234a_c81); version 856.v04c46c86f911 only; version 866.vdea_7dcd3008e only

Published 2024-03-06. Last modified 2026-06-17.