Executive brief
Jenkins is an automation server widely used for continuous integration and deployment across organizations. When configured with the "Delegate to servlet container" security realm, the login flow uses an unvalidated "from" parameter to redirect users after successful authentication. An attacker can craft a malicious link that redirects users to a fake login page or credential-harvesting site, enabling phishing attacks against Jenkins users and potentially compromising their accounts and sensitive data.
Technical details
This is an open redirect vulnerability (CWE-601) in the "Delegate to servlet container" security realm component of Jenkins. The vulnerability exists because the "from" parameter, which specifies where to redirect users after login, is not properly validated to ensure it points to a safe location. An attacker can craft a link with a "from" parameter pointing to an attacker-controlled domain; when a user clicks the link and logs in, they are redirected to the attacker's domain, facilitating phishing attacks. The attack requires user interaction (the user must click the malicious link and log in). No special privileges are required from the attacker. Jenkins 2.568 and LTS 2.555.3 fix this by validating the "from" parameter to ensure it is safe to redirect to after login.
Affected products
- Jenkins Jenkins 2.567 and earlier
- Jenkins Jenkins LTS 2.555.2 and earlier
Timeline
- 2026-06-10: disclosed: Vulnerability disclosed via Jenkins Security Advisory 2026-06-10
- 2026-06-10: patched: Jenkins 2.568 and LTS 2.555.3 released with fixes