Jenkins Bitbucket OAuth Plugin does not restrict the redirect URL after login (CVE-2026-48924) | HOL Guard CVE