Jenkins Google Login Plugin 1.4 through 1.6 (both inclusive) improperly determines that a redirect URL after login is legitimately pointing to Jenkins.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-46683.json"