Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not ensure that the "from" parameter in the "Delegate to servlet container" security realm is safe to redirect to after login, allowing attackers to perform phishing attacks by redirecting users to an attacker-controlled domain.
Metrics
Affected Vendors & Products
References
History
Wed, 10 Jun 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Open Redirect Allows Phishing via Jenkins Login Redirect | |
| Weaknesses | CWE-601 |
Wed, 10 Jun 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not ensure that the "from" parameter in the "Delegate to servlet container" security realm is safe to redirect to after login, allowing attackers to perform phishing attacks by redirecting users to an attacker-controlled domain. | |
| References |
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2026-06-10T14:39:11.982Z
Reserved: 2026-06-09T14:26:44.789Z
Link: CVE-2026-53440
No data.
Status : Received
Published: 2026-06-10T14:16:36.990
Modified: 2026-06-10T14:16:36.990
Link: CVE-2026-53440
No data.
OpenCVE Enrichment
Updated: 2026-06-10T15:00:13Z