ZeroHour

CVE-2026-48924

CVSS 3.1
4.3 medium
EPSS
<1%p11
Published
()
Modified
Description

Jenkins Bitbucket OAuth Plugin 0.17 and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks.

Vendors
jenkins
Products
bitbucket oauth
Weakness
CWE-601
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.