CVE-2020-2287

CWE-4354 documents4 sources
Severity
5.3MEDIUM
No vector
EPSS
0.1%
top 79.50%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 8
Latest updateFeb 10

Description

Jenkins Audit Trail Plugin 3.6 and earlier applies pattern matching to a different representation of request URL paths than the Stapler web framework uses for dispatching requests, which allows attackers to craft URLs that bypass request logging of any target URL.

Affected Packages2 packages

🔴Vulnerability Details

3
OSV
Request logging bypass in Jenkins Audit Trail Plugin2022-02-10
GHSA
Request logging bypass in Jenkins Audit Trail Plugin2022-02-10
CVEList
CVE-2020-2287: Jenkins Audit Trail Plugin 32020-10-08

📋Vendor Advisories

1
Jenkins
Jenkins Security Advisory 2020-10-082020-10-08
CVE-2020-2287 (MEDIUM CVSS 5.3) | Jenkins Audit Trail Plugin 3.6 and | cvebase.io