Description
Jenkins OpenId Connect Authentication Plugin 2.6 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins, allowing attackers to perform phishing attacks.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-9qv8-7jfq-73j2 | Open redirect vulnerability in Jenkins OpenId Connect Authentication Plugin |
References
History
Wed, 28 May 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jenkins openid Connect Authentication
|
|
| CPEs | cpe:2.3:a:jenkins:openid_connect_authentication:*:*:*:*:*:jenkins:*:* | |
| Vendors & Products |
Jenkins openid
|
Jenkins openid Connect Authentication
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2025-02-13T17:19:35.345Z
Reserved: 2023-12-13T13:06:36.477Z
Link: CVE-2023-50771
No data.
Status : Analyzed
Published: 2023-12-13T18:15:44.090
Modified: 2025-05-28T13:54:59.073
Link: CVE-2023-50771
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA