SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-2287

Jenkins Audit Trail Plugin 3.6 and earlier applies pattern matching to a different representation of request URL paths than the Stapler web framework uses for dispatching requests, which allows attackers to craft URLs that bypass request logging of any…

MEDIUM 5.3EPSS 1.17%

Does this matter?

Lower severity and a low EPSS score (1.17%). Track it; it rarely justifies an emergency change on its own.

Description

Jenkins Audit Trail Plugin 3.6 and earlier applies pattern matching to a different representation of request URL paths than the Stapler web framework uses for dispatching requests, which allows attackers to craft URLs that bypass request logging of any target URL.

CVSS 3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
EPSS
1.17% probability · 66th percentile
CISA KEV
Not listed
Affected
jenkins/audit trail
Source
jenkinsci-cert@googlegroups.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.