PT-2026-93784 · Jenkins · Keycloak Authentication Plugin
CVE-2026-92141
·
Published
2026-09-16
·
Updated
2026-09-16
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins Keycloak Authentication Plugin versions prior to 2.4.2
Description
The plugin fails to restrict the redirect URL after the login process. This flaw allows attackers to redirect users to malicious sites, facilitating phishing attacks.
Recommendations
Update Jenkins Keycloak Authentication Plugin to version 2.4.2 or later.
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Keycloak Authentication Plugin