Jenkins 2.227 and earlier, LTS 2.204.5 and earlier uses different representations of request URL paths, which allows attackers to craft URLs that allow bypassing CSRF protection of any target URL.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-3520 | Jenkins 2.227 and earlier, LTS 2.204.5 and earlier uses different representations of request URL paths, which allows attackers to craft URLs that allow bypassing CSRF protection of any target URL. |
Github GHSA |
GHSA-c735-g9f2-2mvp | Cross-Site Request Forgery in Jenkins |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2024-08-04T07:01:40.917Z
Reserved: 2019-12-05T00:00:00
Link: CVE-2020-2160
No data.
Status : Modified
Published: 2020-03-25T17:15:14.907
Modified: 2024-11-21T05:24:49.580
Link: CVE-2020-2160
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA