4.3
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Description
Jenkins Microsoft Entra ID (previously Azure AD) Plugin 666.v6060de32f87d and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks.
Basic Information
ID
CVE-2026-42525
Source
jenkins
Published
Apr 29, 2026 at 13:31
Modified
Apr 29, 2026 at 14:09
Affected Product
Vendor
Jenkins Project
Product
Jenkins Microsoft Entra ID (previously Azure AD) Plugin
Affected Versions
Jenkins Project Jenkins Microsoft Entra ID (previously Azure AD) Plugin 0