CVE-2012-6073Improper Input Validation in Jenkins

Severity
5.8MEDIUMNVD
EPSS
0.3%
top 50.58%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 24
Latest updateMay 14

Description

Open redirect vulnerability in Jenkins before 1.491, Jenkins LTS before 1.480.1, and Jenkins Enterprise 1.424.x before 1.424.6.13, 1.447.x before 1.447.4.1, and 1.466.x before 1.466.10.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

CVSS vector

AV:N/AC:M/C:P/I:P/A:NExploitability: 8.6 | Impact: 4.9

Affected Packages2 packages

NVDjenkins/jenkins1.466.2+50
NVDcloudbees/jenkins1.480.3.1+16

🔴Vulnerability Details

3
OSV
Jenkins affected by Open Redirect Vulnerability2022-05-14
GHSA
Jenkins affected by Open Redirect Vulnerability2022-05-14
CVEList
CVE-2012-6073: Open redirect vulnerability in Jenkins before 12013-02-24

📋Vendor Advisories

2
Jenkins
Jenkins Security Advisory 2012-11-202012-11-20
Red Hat
Jenkins: open redirect2012-11-20

💬Community

1
Bugzilla
CVE-2012-6073 Jenkins: open redirect2012-12-28
CVE-2012-6073 — Improper Input Validation in Jenkins | cvebase