ZeroHour

CVE-2026-42525

CVSS 3.1
4.3 medium
EPSS
<1%p12
Published
()
Modified
Description

Jenkins Microsoft Entra ID (previously Azure AD) Plugin 666.v6060de32f87d and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks.

Vendors
jenkins
Products
azure ad
Weakness
CWE-601
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.