CVE-2020-2160

HIGH

Jenkins < 2.204.6 - Cross-Site Request Forgery Protection Bypass via URL Path Representation

Title source: llm
STIX 2.1

Description

Jenkins 2.227 and earlier, LTS 2.204.5 and earlier uses different representations of request URL paths, which allows attackers to craft URLs that allow bypassing CSRF protection of any target URL.

References (2)

Core 2
Core References
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2020/03/25/2

Scores

CVSS v3 8.8
EPSS 0.0020
EPSS Percentile 41.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-352
Status published
Products (3)
jenkins/jenkins < 2.204.5
jenkins/jenkins < 2.227
org.jenkins-ci.main/jenkins-core 0 - 2.204.6Maven
Published Mar 25, 2020
Tracked Since Feb 18, 2026