Description
Multiple open redirect vulnerabilities in Jenkins before 2.3 and LTS before 1.651.2 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors related to "scheme-relative" URLs.
References (4)
Core 4
Core References
Vendor Advisory x_refsource_confirm
https://www.cloudbees.com/jenkins-security-advisory-2016-05-11
Vendor Advisory x_refsource_confirm
https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2016-05-11
Vendor Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHSA-2016:1206
Vendor Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2016-1773.html
Scores
CVSS v3
7.4
EPSS
0.0008
EPSS Percentile
23.6%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N
Details
Status
published
Products (5)
jenkins/jenkins
< 1.651.1
jenkins/jenkins
< 2.2
org.jenkins-ci.main/jenkins-core
1.652 - 2.3Maven
redhat/openshift
3.1
redhat/openshift
3.2
Published
May 17, 2016
Tracked Since
Feb 18, 2026