CVE-2026-48924: Jenkins Bitbucket OAuth Plugin does not restrict the redirect URL after login
(updated )
Jenkins Bitbucket OAuth Plugin 0.17 and earlier does not restrict the redirect URL after login.
This allows attackers to perform phishing attacks by having users go to a Jenkins URL that will forward them to a different site after successful authentication.
Bitbucket OAuth Plugin 0.18 only redirects to relative (Jenkins) URLs.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-48924 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →