Jenkins Audit Trail Plugin 3.6 and earlier applies pattern matching to a different representation of request URL paths than the Stapler web framework uses for dispatching requests, which allows attackers to craft URLs that bypass request logging of any target URL.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: jenkins
Published: 2020-10-08T12:40:25
Updated: 2024-08-04T07:01:41.267Z
Reserved: 2019-12-05T00:00:00
Link: CVE-2020-2287
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-10-08T13:15:11.407
Modified: 2024-11-21T05:25:12.613
Link: CVE-2020-2287
Redhat
No data.