CVE-2026-53437

⚪ Do wiadomości

Błąd w Jenkins umożliwia ataki phishingowe przez nieprawidłowe przetwarzanie URL po logowaniu.

CVSS
4.3
EPSS
0.4%
Exploit
none
Vendor
jenkins
Opis źródłowy (NVD)

Jenkins 2.567 and earlier, LTS 2.555.2 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins when it contains tab or newline characters between `//`, allowing attackers to perform phishing attacks.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS4.3
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.4%
Opublikowano (NVD)2026-06-10 14:16:36 UTC
Ostatnia modyfikacja (NVD)2026-08-27 13:18:24 UTC
Referencje