← Back

CVE-2026-42525

nvd nist
Published: Apr 29, 2026Modified: Jun 17, 2026

JSON object

Loading...
4.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Exploitability: 2.8 / Impact: 1.4
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

Jenkins Microsoft Entra ID (previously Azure AD) Plugin 666.v6060de32f87d and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks.

Affected (1)

Products: Jenkins: Azure Ad
1 product
Azure Ad
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 666.v6060de32f87d

References (1)

Source: jenkinsci-cert@googlegroups.com
Vendor Advisory

Timeline

No history available yet.