Jenkins 2.567 and earlier, LTS 2.555.2 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins when it contains tab or newline characters between `//`, allowing attackers to perform phishing attacks.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-06-10 14:16
Updated : 2026-08-27 13:18
NVD link : CVE-2026-53437
Mitre link : CVE-2026-53437
CVE.ORG link : CVE-2026-53437
JSON object : View
Products Affected
jenkins
- jenkins
CWE
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')
