« Back to list

Jenkins

Jenkins Bitbucket Oauth: vulnerabilities and CVEs

Jenkins Bitbucket Oauth has 4 published vulnerabilities, 1 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.

CVEs4
Last 12 months1
Critical1
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-48924Medium (4.3)0.33%—May 27, 2026
Jenkins Bitbucket OAuth Plugin 0.17 and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks.
CVE-2023-24428Medium (5.7)0.48%—Jan 26, 2023
A cross-site request forgery (CSRF) vulnerability in Jenkins Bitbucket OAuth Plugin 0.12 and earlier allows attackers to trick users into logging in to the attacker's account.
CVE-2023-24427Critical (9.8)1.1%—Jan 26, 2023
Jenkins Bitbucket OAuth Plugin 0.12 and earlier does not invalidate the previous session on login.
CVE-2019-10460High (7.8)0.33%—Oct 23, 2019
Jenkins Bitbucket OAuth Plugin 0.9 and earlier stored credentials unencrypted in the global config.xml configuration file on the Jenkins master where they could be viewed by users with access to the master file system.

Other products by Jenkins