Jenkins Microsoft Entra ID (previously Azure AD) Plugin 666.v6060de32f87d and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks.
Metrics
Affected Vendors & Products
References
History
Tue, 05 May 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jenkins
Jenkins azure Ad |
|
| CPEs | cpe:2.3:a:jenkins:azure_ad:*:*:*:*:*:jenkins:*:* | |
| Vendors & Products |
Jenkins
Jenkins azure Ad |
Thu, 30 Apr 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jenkins Project
Jenkins Project jenkins Microsoft Entra Id Plugin |
|
| Vendors & Products |
Jenkins Project
Jenkins Project jenkins Microsoft Entra Id Plugin |
Wed, 29 Apr 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unrestricted Redirect in Microsoft Entra ID Plugin Enables Phishing Attacks |
Wed, 29 Apr 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-601 | |
| Metrics |
cvssV3_1
|
Wed, 29 Apr 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Jenkins Microsoft Entra ID (previously Azure AD) Plugin 666.v6060de32f87d and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks. | |
| References |
|
Status: PUBLISHED
Assigner: jenkins
Published: 2026-04-29T13:31:33.582Z
Updated: 2026-04-29T14:09:41.735Z
Reserved: 2026-04-28T09:24:35.049Z
Link: CVE-2026-42525
Updated: 2026-04-29T14:08:53.365Z
Status : Analyzed
Published: 2026-04-29T14:16:19.557
Modified: 2026-05-05T14:25:14.963
Link: CVE-2026-42525
No data.