Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-53436

Опубликовано: 10 июн. 2026
Источник: redhat
CVSS3: 4.3
EPSS Низкий

Описание

Jenkins 2.567 and earlier, LTS 2.555.2 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins when it contains relative path segments (./ or ../), allowing attackers to perform phishing attacks.

A flaw was found in Jenkins. The system improperly validates redirect URLs after login, specifically when they contain relative path segments such as ./ or ../. This vulnerability allows attackers to craft malicious URLs that appear legitimate, leading to successful phishing attacks against users.

Отчет

This Moderate impact flaw in Jenkins, as shipped in OpenShift Developer Tools & Services, allows attackers to conduct phishing attacks. By exploiting improper validation of redirect URLs containing relative path segments, an attacker can craft a malicious link that appears legitimate, deceiving users into revealing sensitive information.

Меры по смягчению последствий

upgrade to Jenkins 2.568 or LTS 2.555.3

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Developer Tools and ServicesjenkinsFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-601
https://bugzilla.redhat.com/show_bug.cgi?id=2487545jenkins: Jenkins: Phishing attacks via improper redirect URL validation

EPSS

Процентиль: 20%
0.00282
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
nvd
около 2 месяцев назад

Jenkins 2.567 and earlier, LTS 2.555.2 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins when it contains relative path segments (`./` or `../`), allowing attackers to perform phishing attacks.

CVSS3: 4.3
github
около 2 месяцев назад

Jenkins 2.567 and earlier, LTS 2.555.2 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins when it contains relative path segments (`./` or `../`), allowing attackers to perform phishing attacks.

EPSS

Процентиль: 20%
0.00282
Низкий

4.3 Medium

CVSS3