CVE-2025-27625 - Jenkins URL Redirects Allow-Path Vulnerability
CVE ID : CVE-2025-27625
Published : March 5, 2025, 11:15 p.m. | 4 hours, 13 minutes ago
Description : In Jenkins 2.499 and earlier, LTS 2.492.1 and earlier, redirects starting with backslash (`\`) characters are considered safe, allowing attackers to perform phishing attacks by having users go to a Jenkins URL that will forward them to a different site, because browsers interpret these characters as part of scheme-relative redirects.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : March 5, 2025, 11:15 p.m. | 4 hours, 13 minutes ago
Description : In Jenkins 2.499 and earlier, LTS 2.492.1 and earlier, redirects starting with backslash (`\`) characters are considered safe, allowing attackers to perform phishing attacks by having users go to a Jenkins URL that will forward them to a different site, because browsers interpret these characters as part of scheme-relative redirects.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...