VulnSea

publish_to_bitbucket vulnerabilities

CVEs whose affected-version data names the publish_to_bitbucket package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

3 CVEsRSS

CVE-2025-64150Medium· 5.4
11mo ago

A missing permission check in Jenkins Publish to Bitbucket Plugin 0.4 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another met…

A missing permission check in Jenkins Publish to Bitbucket Plugin 0.4 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another met…

▾ Sunlitjenkins · publish_to_bitbucketEPSS 0.24%via NVD
CVE-2025-64149Medium· 5.4
11mo ago

A cross-site request forgery (CSRF) vulnerability in Jenkins Publish to Bitbucket Plugin 0.4 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, c…

A cross-site request forgery (CSRF) vulnerability in Jenkins Publish to Bitbucket Plugin 0.4 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, c…

▾ Sunlitjenkins · publish_to_bitbucketEPSS 0.21%via NVD
CVE-2025-64148Medium· 4.3
11mo ago

A missing permission check in Jenkins Publish to Bitbucket Plugin 0.4 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

A missing permission check in Jenkins Publish to Bitbucket Plugin 0.4 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

▾ Sunlitjenkins · publish_to_bitbucketEPSS 0.27%via NVD
publish_to_bitbucket vulnerabilities (CVEs) · VulnSea