Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-53440

Опубликовано: 10 июн. 2026
Источник: redhat
CVSS3: 4.3

Описание

Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not ensure that the "from" parameter in the "Delegate to servlet container" security realm is safe to redirect to after login, allowing attackers to perform phishing attacks by redirecting users to an attacker-controlled domain.

A flaw was found in Jenkins. This vulnerability allows a remote attacker to perform phishing attacks. The 'Delegate to servlet container' security realm does not properly validate the 'from' parameter, which can be manipulated to redirect users to an attacker-controlled domain after they log in. This could trick users into revealing sensitive information.

Отчет

The CVE is rated Moderate (4.3), but the impact on Red Hat products is Low. The Jenkins RPM shipped in ocp-tools includes the vulnerable "Delegate to servlet container" security realm code, but the OpenShift Jenkins image uses the OpenShift Login plugin for authentication by default. The servlet container realm is never active unless an administrator manually switches to it in Jenkins settings, so the vulnerable code path is present but unreachable without deliberate configuration changes.

Меры по смягчению последствий

Verify which security realm your Jenkins instance uses under Manage Jenkins > Security. If it is set to anything other than "Delegate to servlet container" your instance is not affected. If you are using servlet container delegation, switch to one of the other available security realms.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Developer Tools and ServicesjenkinsFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-601
https://bugzilla.redhat.com/show_bug.cgi?id=2487546jenkins: Jenkins: Phishing attacks via unsafe redirection in 'Delegate to servlet container' security realm

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
nvd
около 2 месяцев назад

Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not ensure that the "from" parameter in the "Delegate to servlet container" security realm is safe to redirect to after login, allowing attackers to perform phishing attacks by redirecting users to an attacker-controlled domain.

CVSS3: 4.3
github
около 2 месяцев назад

Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not ensure that the "from" parameter in the "Delegate to servlet container" security realm is safe to redirect to after login, allowing attackers to perform phishing attacks by redirecting users to an attacker-controlled domain.

4.3 Medium

CVSS3