GHSA-r8fj-rff6-f7h5MediumCVSS 4.3

Jenkins Bitbucket OAuth Plugin does not restrict the redirect URL after login

Published
May 27, 2026
Last Modified
July 1, 2026

🔗 CVE IDs covered (1)

📋 Description

Jenkins Bitbucket OAuth Plugin 0.17 and earlier does not restrict the redirect URL after login.

This allows attackers to perform phishing attacks by having users go to a Jenkins URL that will forward them to a different site after successful authentication.

Bitbucket OAuth Plugin 0.18 only redirects to relative (Jenkins) URLs.

🎯 Affected products1

  • maven/org.jenkins-ci.plugins:bitbucket-oauth:<= 0.17

🔗 References (3)