PT-2026-93782 · Jenkins · Bitbucket Push/Pull Request Plugin
CVE-2026-92139
·
Published
2026-09-16
·
Updated
2026-09-16
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins Bitbucket Push and Pull Request Plugin versions prior to 4.0.2
Description
The plugin trusts values provided in the webhook payload, including specific URLs. It uses configured Bitbucket credentials to connect to these URLs, which allows an attacker to capture the stored Bitbucket credentials by sending a crafted webhook payload.
Recommendations
Update the Jenkins Bitbucket Push and Pull Request Plugin to version 4.0.2 or later.
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bitbucket Push/Pull Request Plugin