Jenkins Bitbucket OAuth Plugin
cpe:2.3:a:jenkins:bitbucket_oauth:*:*:*:*:jenkins:*:*
- <= 0.17
An open redirect vulnerability has been identified in the Jenkins Bitbucket OAuth Plugin, affecting versions through 0.17. This vulnerability allows attackers to manipulate the redirect URL after login, potentially leading to phishing attacks. By directing users to a Jenkins URL that forwards them to a different site post-authentication, attackers can exploit this flaw.
Exploitation of this vulnerability could lead to phishing attacks, where users are tricked into providing sensitive information or credentials on a fraudulent website.
Users of the Jenkins Bitbucket OAuth Plugin are advised to update to version 0.18, which restricts redirects to relative Jenkins URLs only.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.