Jenkins 2.567 and earlier, LTS 2.555.2 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins when it contains relative path segments (`./` or `../`), allowing attackers to perform phishing attacks.
CVSS Details
- CVSS 3.1 Base Score: 4.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade jenkins-ltsUpgrade jenkins | Jun 18, 2026 | Jun 17, 2026 |
| Jenkins 2026 06 10 | — | Upgrade Jenkins to version 2.568Upgrade Jenkins LTS to version 2.555.3Upgrade Jenkins to the latest versionUpgrade Jenkins LTS to the latest version | Jul 23, 2026 | Jun 10, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub