Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-53437

Опубликовано: 10 июн. 2026
Источник: redhat
CVSS3: 7.4
EPSS Низкий

Описание

Jenkins 2.567 and earlier, LTS 2.555.2 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins when it contains tab or newline characters between //, allowing attackers to perform phishing attacks.

A flaw was found in Jenkins. This vulnerability allows a remote attacker to perform phishing attacks by crafting a malicious redirect URL. The flaw occurs because Jenkins improperly validates redirect URLs after login, specifically when tab or newline characters are present between the // in the URL. This can trick users into visiting malicious sites, potentially leading to credential theft or other security compromises.

Отчет

This is an Important vulnerability in Jenkins that allows remote attackers to conduct phishing attacks. The flaw stems from improper validation of redirect URLs after login, specifically when tab or newline characters are present, which can be exploited to redirect users to malicious sites. This could lead to credential theft and other security compromises for users interacting with affected Jenkins instances in Red Hat OpenShift Developer Tools & Services.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Developer Tools and ServicesjenkinsAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-601
https://bugzilla.redhat.com/show_bug.cgi?id=2487544jenkins: Jenkins: Phishing attack via improper redirect URL validation

EPSS

Процентиль: 29%
0.00364
Низкий

7.4 High

CVSS3

Связанные уязвимости

CVSS3: 4.3
nvd
около 2 месяцев назад

Jenkins 2.567 and earlier, LTS 2.555.2 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins when it contains tab or newline characters between `//`, allowing attackers to perform phishing attacks.

CVSS3: 4.3
github
около 2 месяцев назад

Jenkins 2.567 and earlier, LTS 2.555.2 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins when it contains tab or newline characters between `//`, allowing attackers to perform phishing attacks.

EPSS

Процентиль: 29%
0.00364
Низкий

7.4 High

CVSS3