Jenkins 2.227 and earlier, LTS 2.204.5 and earlier uses different representations of request URL paths, which allows attackers to craft URLs that allow bypassing CSRF protection of any target URL.
References
Link | Resource |
---|---|
https://jenkins.io/security/advisory/2020-03-25/#SECURITY-1774 | Vendor Advisory |
http://www.openwall.com/lists/oss-security/2020/03/25/2 | Mailing List Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2020-03-25 10:15
Updated : 2020-03-30 12:37
NVD link : CVE-2020-2160
Mitre link : CVE-2020-2160
JSON object : View
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
Products Affected
jenkins
- jenkins