CVE Database
/

CVE-2026-42525

Back to search

CVE-2026-42525

Published: Apr 29, 2026

Modified: Apr 29, 2026

PUBLISHED

Description

Jenkins Microsoft Entra ID (previously Azure AD) Plugin 666.v6060de32f87d and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks.

VendorProductVersions

Jenkins Project

Jenkins Microsoft Entra ID (previously Azure AD) Plugin

affected
0 - <= 666.v6060de32f87d

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now