Description
Jenkins 2.567 and earlier, LTS 2.555.2 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins when it contains tab or newline characters between `//`, allowing attackers to perform phishing attacks.
Remediation
References
Related Vulnerabilities
WordPress Plugin Featured Content 'param' Parameter Cross-Site Scripting (0.0.1)
Liferay Portal Other Vulnerability (CVE-2024-26270)
WordPress Plugin Contest Gallery-Photo Contest for WordPress Cross-Site Request Forgery (10.4.1.1)
TYPO3 Permissions, Privileges, and Access Controls Vulnerability (CVE-2008-2717)