CVE-2023-37947: Jenkins Openshift Login

Medium severity, CVSS 6.1. EPSS: 0.6% chance of exploitation in the next 30 days.

Jenkins OpenShift Login Plugin 1.1.0.227.v27e08dfb_1a_20 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins, allowing attackers to perform phishing attacks.

Affected products

  • Jenkins Openshift Login: before 1.1.0.230.v5d7030b_f5432 (fixed in 1.1.0.230.v5d7030b_f5432)

Published 2023-07-12. Last modified 2026-06-17.