Lucene search

K
osvGoogleOSV:GHSA-2VVR-5757-QP87
HistoryMay 24, 2022 - 7:06 p.m.

Open redirect vulnerability in Jenkins CAS Plugin

2022-05-2419:06:35
Google
osv.dev
13
jenkins
cas plugin
open redirect
vulnerability
phishing
authentication

EPSS

0.001

Percentile

36.1%

Jenkins CAS Plugin 1.6.0 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins.

This allows attackers to perform phishing attacks by having users go to a Jenkins URL that will forward them to a different site after successful authentication.

Jenkins CAS Plugin 1.6.1 only redirects to relative (Jenkins) URLs.

EPSS

0.001

Percentile

36.1%

Related for OSV:GHSA-2VVR-5757-QP87