MEDIUM 4.3 Maven

Jenkins: Open Redirect phishing attacks possible via "from" parameter in "Delegate to servlet container"

GHSA-92m7-4fpw-2wxm · BIT-jenkins-2026-53440 · CVE-2026-53440

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not ensure that the "from" parameter in the "Delegate to servlet container" security realm is safe to redirect to after login, allowing attackers to perform phishing attacks by redirecting users to an attacker-controlled domain.

Ready to move

Start Securing

Free, no credit card | First findings in minutes