Beveiligingsadvies

CVE-2026-53440

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-06-10 13:06:00
Laatst bijgewerkt 2026-06-10 14:39:11
Toegewezen door jenkins
CVSS-score 4.3
Status PUBLISHED

Beschrijving

Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not ensure that the "from" parameter in the "Delegate to servlet container" security realm is safe to redirect to after login, allowing attackers to perform phishing attacks by redirecting users to an attacker-controlled domain.