CVE-2025-27625 - Jenkins URL Redirects Allow-Path Vulnerability

CVE ID : CVE-2025-27625 Published : March 5, 2025, 11:15 p.m. | 2 hours, 14 minutes ago Description : In Jenkins 2.499 and earlier, LTS 2.492.1 and earlier, redirects starting with backslash (`\`) characters are considered safe, allowing attackers to perform phishing attacks by having users go to a Jenkins URL that will forward them to a different site, because browsers interpret these characters as part of scheme-relative redirects. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Mär 6, 2025 - 02:30
 0  0
CVE-2025-27625 - Jenkins URL Redirects Allow-Path Vulnerability
CVE ID : CVE-2025-27625
Published : March 5, 2025, 11:15 p.m. | 2 hours, 14 minutes ago
Description : In Jenkins 2.499 and earlier, LTS 2.492.1 and earlier, redirects starting with backslash (`\`) characters are considered safe, allowing attackers to perform phishing attacks by having users go to a Jenkins URL that will forward them to a different site, because browsers interpret these characters as part of scheme-relative redirects.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...