Impact
The Jenkins Keycloak Authentication Plugin version 2.4.1 and earlier allows an attacker to insert an arbitrary redirect URL after a user logs in, creating an open‑redirect flaw (CWE-601). This enables attackers to lure users to malicious sites that mimic legitimate login pages, facilitating credential harvesting and other phishing attacks. The vulnerability does not grant direct code execution or password exposure on its own, but it can be combined with social engineering to compromise account security.
Affected Systems
All Jenkins installations that use the Keycloak Authentication Plugin 2.4.1 or older are affected. The plugin is distributed by the Jenkins Project and is commonly used to integrate Keycloak as an authentication provider in Jenkins instances.
Risk and Exploitability
The CVSS score of 4.3 indicates a low to moderate severity, and the EPSS score of less than 1% shows a very low probability of exploitation at the time of assessment. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote via the web interface, where an attacker can supply a crafted login URL to redirect the user to a malicious site.
OpenCVE Enrichment