Impact
The Jenkins Bitbucket Server Integration Plugin 6.0.1 and earlier fails to validate the OAuth callback URL stored server‑side. Instead, it accepts a value supplied in the submitted form, enabling an attacker to redirect the OAuth flow to a malicious endpoint and capture the access token that the victim receives. This flaw allows the attacker to obtain provider tokens on behalf of the victim without requiring privileged access to the Jenkins instance. The vulnerability is a classic example of CWE-345 – Data from Alternate Credentials.
Affected Systems
The vulnerability applies to the Jenkins Bitbucket Server Integration Plugin for Jenkins Project. Versions 6.0.1 and earlier are affected; any release newer than 6.0.1 is presumed to contain the fix.
Risk and Exploitability
The flaw has a CVSS score of 4.2, indicating moderate impact. The EPSS score of less than 1% suggests a very low probability of exploitation in the current threat landscape. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit it remotely via the web interface by manipulating the OAuth callback field during the authorization step, which requires only the ability to access the vulnerable plugin endpoint. If successful, the attacker can obtain OAuth access tokens and use them to access the victim’s Bitbucket resources. The impact is limited to the credentials the victim’s account can access, but it can lead to data exposure and potential lateral movement.
OpenCVE Enrichment