Jenkins
Jenkins Bitbucket Oauth: vulnerabilities and CVEs
Jenkins Bitbucket Oauth has 4 published vulnerabilities, 1 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.
CVEs4
Last 12 months1
Critical1
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-48924 | Medium (4.3) | 0.33% | — | May 27, 2026 | Jenkins Bitbucket OAuth Plugin 0.17 and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks. |
| CVE-2023-24428 | Medium (5.7) | 0.48% | — | Jan 26, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins Bitbucket OAuth Plugin 0.12 and earlier allows attackers to trick users into logging in to the attacker's account. |
| CVE-2023-24427 | Critical (9.8) | 1.1% | — | Jan 26, 2023 | Jenkins Bitbucket OAuth Plugin 0.12 and earlier does not invalidate the previous session on login. |
| CVE-2019-10460 | High (7.8) | 0.33% | — | Oct 23, 2019 | Jenkins Bitbucket OAuth Plugin 0.9 and earlier stored credentials unencrypted in the global config.xml configuration file on the Jenkins master where they could be viewed by users with access to the master file system. |