PT-2026-44017 · Jenkins · Bitbucket Oauth Plugin
Dyingman1
·
Published
2026-05-27
·
Updated
2026-05-27
·
CVE-2026-48924
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins Bitbucket OAuth Plugin versions prior to 0.18
Description
The plugin fails to restrict the redirect URL after the login process, which enables attackers to conduct phishing attacks via open redirection.
Recommendations
Update to a version later than 0.17.
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bitbucket Oauth Plugin