Feed/CVE-2026-48924
CVE-2026-48924MEDIUMCVSS 4.3

Jenkins Bitbucket OAuth Plugin does not restrict the redirect URL after login

Published May 27, 2026·Updated Jul 1, 2026

NVD Description

Jenkins Bitbucket OAuth Plugin 0.17 and earlier does not restrict the redirect URL after login. This allows attackers to perform phishing attacks by having users go to a Jenkins URL that will forward them to a different site after successful authentication. Bitbucket OAuth Plugin 0.18 only redirects to relative (Jenkins) URLs.

Affected Packages (1)

org.jenkins-ci.plugins:bitbucket-oauthMAVEN
Fixed in = 0.17

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free