PT-2026-75955 · Maven · Org.Jenkins-Ci.Main:Jenkins-Core

Publicado

2026-06-10

·

Atualizado

2026-06-10

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not ensure that the "from" parameter in the "Delegate to servlet container" security realm is safe to redirect to after login, allowing attackers to perform phishing attacks by redirecting users to an attacker-controlled domain.

Correção

Open Redirect

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

GHSA-92M7-4FPW-2WXM

Produtos afetados

Org.Jenkins-Ci.Main:Jenkins-Core