Junglewise Threat Intelligence

CVE-2025-64149: Jenkins Publish to Bitbucket Plugin vulnerable to CSRF and missing permissions check

CVE-2025-64149 · Severity: low · CVSS 3.1 · Published 2025-10-29

Technologies: org.jenkins-ci.plugins:publish-to-bitbucket (Maven). Vendors: Maven.

Executive brief

Jenkins Publish to Bitbucket Plugin vulnerable to CSRF and missing permissions check

Affected products

  • Maven org.jenkins-ci.plugins:publish-to-bitbucket

Related threats