REDHAT-BUG-2487544: High severity Jenkins Jenkins vulnerability
Jenkins 2.567 and earlier, LTS 2.555.2 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins when it contains tab or newline characters between //, allowing attackers to perform phishing attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2487544?
The severity of REDHAT-BUG-2487544 is rated as high with a score of 7.
How does REDHAT-BUG-2487544 affect Jenkins users?
REDHAT-BUG-2487544 allows attackers to exploit redirect URLs with tab or newline characters, enabling phishing attacks on Jenkins users.
How do I fix REDHAT-BUG-2487544?
To fix REDHAT-BUG-2487544, update Jenkins to version 2.568 or later, or LTS version 2.555.3 or later.
What versions of Jenkins are affected by REDHAT-BUG-2487544?
Jenkins versions 2.567 and earlier, as well as Jenkins LTS 2.555.2 and earlier, are affected by REDHAT-BUG-2487544.
What kind of attacks are possible due to REDHAT-BUG-2487544?
REDHAT-BUG-2487544 could lead to phishing attacks, as it improperly validates redirect URLs.