CVE-2020-2287

MEDIUM

Jenkins Audit Trail Plugin <3.6 - SSRF

Title source: llm
STIX 2.1

Description

Jenkins Audit Trail Plugin 3.6 and earlier applies pattern matching to a different representation of request URL paths than the Stapler web framework uses for dispatching requests, which allows attackers to craft URLs that bypass request logging of any target URL.

References (2)

Core 2
Core References
Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2020/10/08/5

Scores

CVSS v3 5.3
EPSS 0.0007
EPSS Percentile 20.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Details

Status published
Products (2)
jenkins/audit_trail < 3.6
org.jenkins-ci.plugins/audit-trail 0 - 3.7Maven
Published Oct 08, 2020
Tracked Since Feb 18, 2026