CVE-2026-48924
published 2026-05-27CVE-2026-48924: Jenkins Bitbucket OAuth Plugin 0.17 and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks.
PriorityP420medium4.3CVSS 3.1
AVNACLPRNUIRSUCNILAN
EPSS
0.22%
12.0th percentile
Jenkins Bitbucket OAuth Plugin 0.17 and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | active_directory | — | — |
| jenkins | active_directory_plugin | — | — |
| jenkins | appspider | — | — |
| jenkins | appspider_plugin | — | — |
| jenkins | bitbucket_oauth | <= 0.17 | — |
| jenkins | bitbucket_oauth | — | — |
| jenkins | bitbucket_oauth_plugin | — | — |
| jenkins | credentials_binding | — | — |
| jenkins | credentials_binding_plugin | — | — |
| jenkins | email_extension | — | — |
| jenkins | email_extension_plugin | — | — |
| jenkins | github_integration | — | — |
| jenkins | github_integration_plugin | — | — |
| jenkins | groovy_libraries | — | — |
| jenkins | groovy_libraries_plugin | — | — |
| jenkins | job_import | — | — |
| jenkins | job_import_plugin | — | — |
| jenkins | ldap | — | — |
| jenkins | ldap_plugin | — | — |
| jenkins | ldap_referrals_in_active_directory | — | — |
| jenkins | ldap_referrals_in_active_directory_plugin | — | — |
| jenkins | multijob | — | — |
| jenkins | multijob_plugin | — | — |
| jenkins_project | jenkins_bitbucket_oauth_plugin | <= 0.17 | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
vendor_oracle4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Jenkins Bitbucket OAuth Plugin does not restrict the redirect URL after login
ghsa·2026-05-27
CVE-2026-48924 [MEDIUM] CWE-601 Jenkins Bitbucket OAuth Plugin does not restrict the redirect URL after login
Jenkins Bitbucket OAuth Plugin does not restrict the redirect URL after login
Jenkins Bitbucket OAuth Plugin 0.17 and earlier does not restrict the redirect URL after login.
This allows attackers to perform phishing attacks by having users go to a Jenkins URL that will forward them to a different site after successful authentication.
Bitbucket OAuth Plugin 0.18 only redirects to relative (Jenkins) URLs.
VulDB
Bitbucket OAuth Plugin up to 0.17 on Jenkins URL redirect
vuldb·2026-05-27·CVSS 4.3
CVE-2026-48924 [MEDIUM] Bitbucket OAuth Plugin up to 0.17 on Jenkins URL redirect
A vulnerability, which was classified as problematic, was found in Bitbucket OAuth Plugin up to 0.17 on Jenkins. This vulnerability affects unknown code of the component URL Handler. Executing a manipulation can lead to open redirect.
The identification of this vulnerability is CVE-2026-48924. The attack may be launched remotely. There is no exploit available.
GHSA
GHSA-r8fj-rff6-f7h5: Jenkins Bitbucket OAuth Plugin 0
ghsa_unreviewed·2026-05-27
CVE-2026-48924 [MEDIUM] CWE-601 GHSA-r8fj-rff6-f7h5: Jenkins Bitbucket OAuth Plugin 0
Jenkins Bitbucket OAuth Plugin 0.17 and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks.
Jenkins
Jenkins Security Advisory 2026-05-27
vendor_jenkins·2026-05-27·CVSS 6.6
CVE-2026-48916 [MEDIUM] Jenkins Security Advisory 2026-05-27
Title: Jenkins Security Advisory 2026-05-27
Jenkins Security Advisory 2026-05-27
Jenkins Security Home
For Administrators
Overview
Terminology
Vulnerabilities and Scoring
Security Advisories
Security Issues
Advisory Schedule
Vulnerabilities in Plugins
How We Fix Security Issues
For Reporters
Reporting Vulnerabilities
Jenkins CNA
For Maintainers
Overview
Vulnerabilities in Plugins
Jenkins Security Team
About
Contributions
This advisory announces vulnerabilities in the following Jenkins deliverables:
Active Directory
Plugin
AppSpider
Plugin
Bitbucket OAuth
Plugin
buildgraph-view
Plugin
Credentials Binding
Plugin
Email Extension
Plugin
GitHub Integration
Plugin
Oracle
Oracle Oracle GoldenGate Risk Matrix: General (Apache Commons Lang) — CVE-2025-48924
vendor_oracle·2026-01-15·CVSS 4.3
CVE-2025-48924 [MEDIUM] Oracle Oracle GoldenGate Risk Matrix: General (Apache Commons Lang) — CVE-2025-48924
Oracle Oracle GoldenGate Risk Matrix: General (Apache Commons Lang) vulnerability
CVE: CVE-2025-48924
CVSS: 4.3
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpujan2026 (JAN 2026)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-48924 slf4j: Uncontrolled Recursion vulnerability in Apache Commons Lang [fedora-42]
bugzilla·2025-07-11·CVSS 5.3
CVE-2025-48924 [MEDIUM] CVE-2025-48924 slf4j: Uncontrolled Recursion vulnerability in Apache Commons Lang [fedora-42]
CVE-2025-48924 slf4j: Uncontrolled Recursion vulnerability in Apache Commons Lang [fedora-42]
More information about this security flaw is available in the following bug:
https://bugzilla.redhat.com/show_bug.cgi?id=2379554
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will be closed as EOL if it remains open with a
'version' of '
Bugzilla
CVE-2025-48924 apache-commons-text: Uncontrolled Recursion vulnerability in Apache Commons Lang [fedora-42]
bugzilla·2025-07-11·CVSS 5.3
CVE-2025-48924 [MEDIUM] CVE-2025-48924 apache-commons-text: Uncontrolled Recursion vulnerability in Apache Commons Lang [fedora-42]
CVE-2025-48924 apache-commons-text: Uncontrolled Recursion vulnerability in Apache Commons Lang [fedora-42]
More information about this security flaw is available in the following bug:
https://bugzilla.redhat.com/show_bug.cgi?id=2379554
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will be closed as EOL if it remains open with a
Bugzilla
CVE-2025-48924 apache-commons-compress: Uncontrolled Recursion vulnerability in Apache Commons Lang [fedora-42]
bugzilla·2025-07-11·CVSS 5.3
CVE-2025-48924 [MEDIUM] CVE-2025-48924 apache-commons-compress: Uncontrolled Recursion vulnerability in Apache Commons Lang [fedora-42]
CVE-2025-48924 apache-commons-compress: Uncontrolled Recursion vulnerability in Apache Commons Lang [fedora-42]
More information about this security flaw is available in the following bug:
https://bugzilla.redhat.com/show_bug.cgi?id=2379554
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will be closed as EOL if it remains open wit
Bugzilla
CVE-2025-48924 velocity: Uncontrolled Recursion vulnerability in Apache Commons Lang [fedora-42]
bugzilla·2025-07-11·CVSS 5.3
CVE-2025-48924 [MEDIUM] CVE-2025-48924 velocity: Uncontrolled Recursion vulnerability in Apache Commons Lang [fedora-42]
CVE-2025-48924 velocity: Uncontrolled Recursion vulnerability in Apache Commons Lang [fedora-42]
More information about this security flaw is available in the following bug:
https://bugzilla.redhat.com/show_bug.cgi?id=2379554
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will be closed as EOL if it remains open with a
'version' o
Bugzilla
CVE-2025-48924 jetty: Uncontrolled Recursion vulnerability in Apache Commons Lang [fedora-42]
bugzilla·2025-07-11·CVSS 5.3
CVE-2025-48924 [MEDIUM] CVE-2025-48924 jetty: Uncontrolled Recursion vulnerability in Apache Commons Lang [fedora-42]
CVE-2025-48924 jetty: Uncontrolled Recursion vulnerability in Apache Commons Lang [fedora-42]
More information about this security flaw is available in the following bug:
https://bugzilla.redhat.com/show_bug.cgi?id=2379554
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will be closed as EOL if it remains open with a
'version' of '
Bugzilla
CVE-2025-48924 replacer: Uncontrolled Recursion vulnerability in Apache Commons Lang [fedora-42]
bugzilla·2025-07-11·CVSS 5.3
CVE-2025-48924 [MEDIUM] CVE-2025-48924 replacer: Uncontrolled Recursion vulnerability in Apache Commons Lang [fedora-42]
CVE-2025-48924 replacer: Uncontrolled Recursion vulnerability in Apache Commons Lang [fedora-42]
More information about this security flaw is available in the following bug:
https://bugzilla.redhat.com/show_bug.cgi?id=2379554
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will be closed as EOL if it remains open with a
'version' o
Bugzilla
CVE-2025-48924 plexus-compiler: Uncontrolled Recursion vulnerability in Apache Commons Lang [fedora-42]
bugzilla·2025-07-11·CVSS 5.3
CVE-2025-48924 [MEDIUM] CVE-2025-48924 plexus-compiler: Uncontrolled Recursion vulnerability in Apache Commons Lang [fedora-42]
CVE-2025-48924 plexus-compiler: Uncontrolled Recursion vulnerability in Apache Commons Lang [fedora-42]
More information about this security flaw is available in the following bug:
https://bugzilla.redhat.com/show_bug.cgi?id=2379554
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will be closed as EOL if it remains open with a
'ver
Bugzilla
CVE-2025-48924 pdftk-java: Uncontrolled Recursion vulnerability in Apache Commons Lang [fedora-42]
bugzilla·2025-07-11·CVSS 5.3
CVE-2025-48924 [MEDIUM] CVE-2025-48924 pdftk-java: Uncontrolled Recursion vulnerability in Apache Commons Lang [fedora-42]
CVE-2025-48924 pdftk-java: Uncontrolled Recursion vulnerability in Apache Commons Lang [fedora-42]
More information about this security flaw is available in the following bug:
https://bugzilla.redhat.com/show_bug.cgi?id=2379554
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
Jon, why did you file this report against the pdftk-java RPM package? The security flaw is in the apache-commons-lang3 RPM package, if I am not completely mistaken…
---
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
Bugzilla
CVE-2025-48924 bcel: Uncontrolled Recursion vulnerability in Apache Commons Lang [fedora-42]
bugzilla·2025-07-11·CVSS 5.3
CVE-2025-48924 [MEDIUM] CVE-2025-48924 bcel: Uncontrolled Recursion vulnerability in Apache Commons Lang [fedora-42]
CVE-2025-48924 bcel: Uncontrolled Recursion vulnerability in Apache Commons Lang [fedora-42]
More information about this security flaw is available in the following bug:
https://bugzilla.redhat.com/show_bug.cgi?id=2379554
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will be closed as EOL if it remains open with a
'version' of '4
Bugzilla
CVE-2025-48924 fusesource-pom: Uncontrolled Recursion vulnerability in Apache Commons Lang [fedora-42]
bugzilla·2025-07-11·CVSS 5.3
CVE-2025-48924 [MEDIUM] CVE-2025-48924 fusesource-pom: Uncontrolled Recursion vulnerability in Apache Commons Lang [fedora-42]
CVE-2025-48924 fusesource-pom: Uncontrolled Recursion vulnerability in Apache Commons Lang [fedora-42]
More information about this security flaw is available in the following bug:
https://bugzilla.redhat.com/show_bug.cgi?id=2379554
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will be closed as EOL if it remains open with a
'vers
Bugzilla
CVE-2025-48924 log4j: Uncontrolled Recursion vulnerability in Apache Commons Lang [fedora-42]
bugzilla·2025-07-11·CVSS 5.3
CVE-2025-48924 [MEDIUM] CVE-2025-48924 log4j: Uncontrolled Recursion vulnerability in Apache Commons Lang [fedora-42]
CVE-2025-48924 log4j: Uncontrolled Recursion vulnerability in Apache Commons Lang [fedora-42]
More information about this security flaw is available in the following bug:
https://bugzilla.redhat.com/show_bug.cgi?id=2379554
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will be closed as EOL if it remains open with a
'version' of '
Bugzilla
CVE-2025-48924 qdox: Uncontrolled Recursion vulnerability in Apache Commons Lang [fedora-42]
bugzilla·2025-07-11·CVSS 5.3
CVE-2025-48924 [MEDIUM] CVE-2025-48924 qdox: Uncontrolled Recursion vulnerability in Apache Commons Lang [fedora-42]
CVE-2025-48924 qdox: Uncontrolled Recursion vulnerability in Apache Commons Lang [fedora-42]
More information about this security flaw is available in the following bug:
https://bugzilla.redhat.com/show_bug.cgi?id=2379554
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will be closed as EOL if it remains open with a
'version' of '4
Bugzilla
CVE-2025-48924 apache-commons-vfs: Uncontrolled Recursion vulnerability in Apache Commons Lang [fedora-42]
bugzilla·2025-07-11·CVSS 5.3
CVE-2025-48924 [MEDIUM] CVE-2025-48924 apache-commons-vfs: Uncontrolled Recursion vulnerability in Apache Commons Lang [fedora-42]
CVE-2025-48924 apache-commons-vfs: Uncontrolled Recursion vulnerability in Apache Commons Lang [fedora-42]
More information about this security flaw is available in the following bug:
https://bugzilla.redhat.com/show_bug.cgi?id=2379554
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will be closed as EOL if it remains open with a
'
Bugzilla
CVE-2025-48924 jackson-modules-base: Uncontrolled Recursion vulnerability in Apache Commons Lang [fedora-42]
bugzilla·2025-07-11·CVSS 5.3
CVE-2025-48924 [MEDIUM] CVE-2025-48924 jackson-modules-base: Uncontrolled Recursion vulnerability in Apache Commons Lang [fedora-42]
CVE-2025-48924 jackson-modules-base: Uncontrolled Recursion vulnerability in Apache Commons Lang [fedora-42]
More information about this security flaw is available in the following bug:
https://bugzilla.redhat.com/show_bug.cgi?id=2379554
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will be closed as EOL if it remains open with a
Bugzilla
CVE-2025-48924 maven-surefire: Uncontrolled Recursion vulnerability in Apache Commons Lang [fedora-42]
bugzilla·2025-07-11·CVSS 5.3
CVE-2025-48924 [MEDIUM] CVE-2025-48924 maven-surefire: Uncontrolled Recursion vulnerability in Apache Commons Lang [fedora-42]
CVE-2025-48924 maven-surefire: Uncontrolled Recursion vulnerability in Apache Commons Lang [fedora-42]
More information about this security flaw is available in the following bug:
https://bugzilla.redhat.com/show_bug.cgi?id=2379554
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will be closed as EOL if it remains open with a
'vers
2026-05-27
Published