Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not ensure that the "from" parameter in the "Delegate to servlet container" security realm is safe to redirect to after login, allowing attackers to perform phishing attacks by redirecting users to an attacker-controlled domain.
References
| Link | Resource |
|---|---|
| https://www.jenkins.io/security/advisory/2026-06-10/#SECURITY-3721 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
12 Jun 2026, 01:03
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:* cpe:2.3:a:jenkins:jenkins:*:*:*:*:-:*:*:* |
|
| First Time |
Jenkins jenkins
Jenkins |
|
| References | () https://www.jenkins.io/security/advisory/2026-06-10/#SECURITY-3721 - Vendor Advisory |
10 Jun 2026, 16:17
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.3 |
| CWE | CWE-601 |
10 Jun 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-10 14:16
Updated : 2026-06-17 10:57
NVD link : CVE-2026-53440
Mitre link : CVE-2026-53440
CVE.ORG link : CVE-2026-53440
JSON object : View
Products Affected
jenkins
- jenkins
CWE
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')
