ZeroHour

CVE-2020-2160

CVSS 3.1
8.8 high
EPSS
2%p80
Published
()
Modified
Description

Jenkins 2.227 and earlier, LTS 2.204.5 and earlier uses different representations of request URL paths, which allows attackers to craft URLs that allow bypassing CSRF protection of any target URL.

Vendors
jenkins
Products
jenkins
Weakness
CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.