4.3
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Description
Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not ensure that the "from" parameter in the "Delegate to servlet container" security realm is safe to redirect to after login, allowing attackers to perform phishing attacks by redirecting users to an attacker-controlled domain.
Basic Information
ID
CVE-2026-53440
Source
jenkins
Published
Jun 10, 2026 at 13:06
Modified
Jun 10, 2026 at 14:39
Affected Product
Vendor
Jenkins Project
Product
Jenkins
Version
2.568