CVE-2025-24398: Jenkins Bitbucket Server Integration

High severity, CVSS 8.8. EPSS: 0.3% chance of exploitation in the next 30 days.

Jenkins Bitbucket Server Integration Plugin 2.1.0 through 4.1.3 (both inclusive) allows attackers to craft URLs that would bypass the CSRF protection of any target URL in Jenkins.

Affected products

  • Jenkins Bitbucket Server Integration: from 2.1.0, before 4.1.4 (fixed in 4.1.4)

Published 2025-01-22. Last modified 2026-06-17.