CVE Watchtower


← Back to CVE List

CVE-2025-64149NVD

Vulnerability Summary

A cross-site request forgery (CSRF) vulnerability in Jenkins Publish to Bitbucket Plugin 0.4 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
Severity Level
UNKNOWN
Published Date
Oct 29, 2025
Last Modified
Oct 29, 2025
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
Data Pending
Root Weakness (CWE)
N/A