-
CVSS Score
-The commit diff shows the vulnerability was fixed by adding Util.isSafeToRedirectTo validation. The original code in determineTargetUrl processed redirect URLs by simply checking context path prefix but didn't validate domain safety. This allowed crafted URLs to redirect users externally. The vulnerable version lacked the security check present in the patched version (1.6.1), making this function the clear entry point for open redirects.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.jenkins-ci.plugins:cas-plugin | maven | <= 1.6.0 | 1.6.1 |
A Semantic Attack on Google Gemini - Read the Latest Research