Jenkins 2.227 and earlier, LTS 2.204.5 and earlier uses different representations of request URL paths, which allows attackers to craft URLs that allow bypassing CSRF protection of any target URL.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade jenkins | May 8, 2020 | Mar 25, 2020 |
| Freebsd | — | Upgrade jenkins-ltsUpgrade jenkins | Mar 26, 2020 | Mar 25, 2020 |
| Jenkins 2020 03 25 | — | Upgrade Jenkins to version 2.228Upgrade Jenkins LTS to version 2.204.6Upgrade Jenkins LTS to the latest versionUpgrade Jenkins to the latest version | Mar 27, 2020 | Mar 25, 2020 |
| Redhat Openshift | — | Upgrade openshift-kuryrUpgrade jenkinsUpgrade openshiftUpgrade atomic-enterprise-service-catalogUpgrade openshift-ansibleUpgrade openshift-clientsUpgrade atomic-openshift-service-idlerUpgrade machine-config-daemonUpgrade conmonUpgrade s390utilsUpgrade cri-o | Dec 29, 2020 | Mar 25, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub