PT-2026-75955 · Maven · Org.Jenkins-Ci.Main:Jenkins-Core

Published

2026-06-10

·

Updated

2026-06-10

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not ensure that the "from" parameter in the "Delegate to servlet container" security realm is safe to redirect to after login, allowing attackers to perform phishing attacks by redirecting users to an attacker-controlled domain.

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-92M7-4FPW-2WXM

Affected Products

Org.Jenkins-Ci.Main:Jenkins-Core