Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-92m7-4fpw-2wxm

Опубликовано: 10 июн. 2026
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

Jenkins: Open Redirect phishing attacks possible via "from" parameter in "Delegate to servlet container"

Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not ensure that the "from" parameter in the "Delegate to servlet container" security realm is safe to redirect to after login, allowing attackers to perform phishing attacks by redirecting users to an attacker-controlled domain.

Пакеты

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

< 2.555.3

2.555.3

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

>= 2.556, < 2.568

2.568

EPSS

Процентиль: 15%
0.00239
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-601

Связанные уязвимости

CVSS3: 4.3
redhat
2 месяца назад

Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not ensure that the "from" parameter in the "Delegate to servlet container" security realm is safe to redirect to after login, allowing attackers to perform phishing attacks by redirecting users to an attacker-controlled domain.

CVSS3: 4.3
nvd
2 месяца назад

Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not ensure that the "from" parameter in the "Delegate to servlet container" security realm is safe to redirect to after login, allowing attackers to perform phishing attacks by redirecting users to an attacker-controlled domain.

CVSS3: 4.3
redos
3 дня назад

Уязвимость jenkins

EPSS

Процентиль: 15%
0.00239
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-601