Jenkins Microsoft Entra ID (previously Azure AD) Plugin 666.v6060de32f87d and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks.
Metrics
Affected Vendors & Products
References
History
Wed, 29 Apr 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-601 | |
| Metrics |
cvssV3_1
|
Wed, 29 Apr 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Jenkins Microsoft Entra ID (previously Azure AD) Plugin 666.v6060de32f87d and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks. | |
| References |
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2026-04-29T14:09:41.735Z
Reserved: 2026-04-28T09:24:35.049Z
Link: CVE-2026-42525
Updated: 2026-04-29T14:08:53.365Z
Status : Received
Published: 2026-04-29T14:16:19.557
Modified: 2026-04-29T15:16:07.377
Link: CVE-2026-42525
No data.
OpenCVE Enrichment
No data.