CVE-2023-50771: Jenkins Openid Connect Authentication
Medium severity, CVSS 6.1. EPSS: 0.6% chance of exploitation in the next 30 days.
Jenkins OpenId Connect Authentication Plugin 2.6 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins, allowing attackers to perform phishing attacks.
Affected products
- Jenkins Openid Connect Authentication: up to and including 2.6
Published 2023-12-13. Last modified 2026-06-17.