jenkins: CSRF protection bypass via crafted URLs
Published Mar 25, 2020
8.8
HIGHCVSS 3.1
EPSS 2.04%
Description
Jenkins 2.227 and earlier, LTS 2.204.5 and earlier uses different representations of request URL paths, which allows attackers to craft URLs that allow bypassing CSRF protection of any target URL.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<=2.227
- Version unspecifiedStatusaffectedConstraints<=LTS 2.204.5
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Jenkins project | Jenkins | n/a |
|
No data.
Red Hat OpenShift Container Platform 3.11
jenkins-0:2.222.1.1591351669-1.el7
Fixed · RHBA-2020:2477
Red Hat OpenShift Container Platform 4.3
atomic-enterprise-service-catalog-1:4.3.25-202006081518.git.1.52b3a66.el7
Fixed · RHBA-2020:2435
Red Hat OpenShift Container Platform 4.3
atomic-openshift-service-idler-0:4.3.25-202006081518.git.1.79365c5.el7
Fixed · RHBA-2020:2435
Red Hat OpenShift Container Platform 4.3
conmon-2:2.0.17-1.rhaos4.3.el7
Fixed · RHBA-2020:2435
Red Hat OpenShift Container Platform 4.3
cri-o-0:1.16.6-15.dev.rhaos4.3.gitebc053b.el7
Fixed · RHBA-2020:2435
Red Hat OpenShift Container Platform 4.3
jenkins-0:2.222.1.1591349991-1.el7
Fixed · RHBA-2020:2435
Red Hat OpenShift Container Platform 4.3
machine-config-daemon-0:4.3.25-202006081518.git.1.478b31a.el8
Fixed · RHBA-2020:2435
Red Hat OpenShift Container Platform 4.3
openshift-0:4.3.25-202006060952.git.1.96c30f6.el7
Fixed · RHBA-2020:2435
Red Hat OpenShift Container Platform 4.3
openshift-ansible-0:4.3.25-202006060952.git.1.1253fde.el7
Fixed · RHBA-2020:2435
Red Hat OpenShift Container Platform 4.3
openshift-clients-0:4.3.25-202006060952.git.1.fd93102.el7
Fixed · RHBA-2020:2435
Red Hat OpenShift Container Platform 4.3
openshift-kuryr-0:4.3.25-202006081518.git.1.240b401.el8
Fixed · RHBA-2020:2435
Red Hat OpenShift Container Platform 4.3
s390utils-2:2.6.0-23.el8
Fixed · RHBA-2020:2435
Red Hat OpenShift Container Platform 4.4
atomic-enterprise-service-catalog-1:4.4.0-202006080017.git.1.77a5cc9.el7
Fixed · RHBA-2020:2444
Red Hat OpenShift Container Platform 4.4
atomic-openshift-service-idler-0:4.4.0-202006080017.git.1.7e463c3.el7
Fixed · RHBA-2020:2444
Red Hat OpenShift Container Platform 4.4
conmon-2:2.0.17-1.rhaos4.4.el7
Fixed · RHBA-2020:2444
Red Hat OpenShift Container Platform 4.4
cri-o-0:1.17.4-14.dev.rhaos4.4.gitb93af5d.el7
Fixed · RHBA-2020:2444
Red Hat OpenShift Container Platform 4.4
jenkins-0:2.222.1.1591351066-1.el7
Fixed · RHBA-2020:2444
Red Hat OpenShift Container Platform 4.4
machine-config-daemon-0:4.4.0-202006080017.git.1.32e0736.el8
Fixed · RHBA-2020:2444
Red Hat OpenShift Container Platform 4.4
openshift-0:4.4.0-202006061254.git.1.dc84fb4.el7
Fixed · RHBA-2020:2444
Red Hat OpenShift Container Platform 4.4
openshift-ansible-0:4.4.0-202006061254.git.1.a996454.el7
Fixed · RHBA-2020:2444
Red Hat OpenShift Container Platform 4.4
openshift-clients-0:4.4.0-202006061254.git.1.26cb6dc.el7
Fixed · RHBA-2020:2444
Red Hat OpenShift Container Platform 4.4
openshift-kuryr-0:4.4.0-202006080017.git.1.855ef1d.el8
Fixed · RHBA-2020:2444
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Container Platform 3.11 | jenkins-0:2.222.1.1591351669-1.el7 | Fixed | RHBA-2020:2477 |
| Red Hat OpenShift Container Platform 4.3 | atomic-enterprise-service-catalog-1:4.3.25-202006081518.git.1.52b3a66.el7 | Fixed | RHBA-2020:2435 |
| Red Hat OpenShift Container Platform 4.3 | atomic-openshift-service-idler-0:4.3.25-202006081518.git.1.79365c5.el7 | Fixed | RHBA-2020:2435 |
| Red Hat OpenShift Container Platform 4.3 | conmon-2:2.0.17-1.rhaos4.3.el7 | Fixed | RHBA-2020:2435 |
| Red Hat OpenShift Container Platform 4.3 | cri-o-0:1.16.6-15.dev.rhaos4.3.gitebc053b.el7 | Fixed | RHBA-2020:2435 |
| Red Hat OpenShift Container Platform 4.3 | jenkins-0:2.222.1.1591349991-1.el7 | Fixed | RHBA-2020:2435 |
| Red Hat OpenShift Container Platform 4.3 | machine-config-daemon-0:4.3.25-202006081518.git.1.478b31a.el8 | Fixed | RHBA-2020:2435 |
| Red Hat OpenShift Container Platform 4.3 | openshift-0:4.3.25-202006060952.git.1.96c30f6.el7 | Fixed | RHBA-2020:2435 |
| Red Hat OpenShift Container Platform 4.3 | openshift-ansible-0:4.3.25-202006060952.git.1.1253fde.el7 | Fixed | RHBA-2020:2435 |
| Red Hat OpenShift Container Platform 4.3 | openshift-clients-0:4.3.25-202006060952.git.1.fd93102.el7 | Fixed | RHBA-2020:2435 |
| Red Hat OpenShift Container Platform 4.3 | openshift-kuryr-0:4.3.25-202006081518.git.1.240b401.el8 | Fixed | RHBA-2020:2435 |
| Red Hat OpenShift Container Platform 4.3 | s390utils-2:2.6.0-23.el8 | Fixed | RHBA-2020:2435 |
| Red Hat OpenShift Container Platform 4.4 | atomic-enterprise-service-catalog-1:4.4.0-202006080017.git.1.77a5cc9.el7 | Fixed | RHBA-2020:2444 |
| Red Hat OpenShift Container Platform 4.4 | atomic-openshift-service-idler-0:4.4.0-202006080017.git.1.7e463c3.el7 | Fixed | RHBA-2020:2444 |
| Red Hat OpenShift Container Platform 4.4 | conmon-2:2.0.17-1.rhaos4.4.el7 | Fixed | RHBA-2020:2444 |
| Red Hat OpenShift Container Platform 4.4 | cri-o-0:1.17.4-14.dev.rhaos4.4.gitb93af5d.el7 | Fixed | RHBA-2020:2444 |
| Red Hat OpenShift Container Platform 4.4 | jenkins-0:2.222.1.1591351066-1.el7 | Fixed | RHBA-2020:2444 |
| Red Hat OpenShift Container Platform 4.4 | machine-config-daemon-0:4.4.0-202006080017.git.1.32e0736.el8 | Fixed | RHBA-2020:2444 |
| Red Hat OpenShift Container Platform 4.4 | openshift-0:4.4.0-202006061254.git.1.dc84fb4.el7 | Fixed | RHBA-2020:2444 |
| Red Hat OpenShift Container Platform 4.4 | openshift-ansible-0:4.4.0-202006061254.git.1.a996454.el7 | Fixed | RHBA-2020:2444 |
| Red Hat OpenShift Container Platform 4.4 | openshift-clients-0:4.4.0-202006061254.git.1.26cb6dc.el7 | Fixed | RHBA-2020:2444 |
| Red Hat OpenShift Container Platform 4.4 | openshift-kuryr-0:4.4.0-202006080017.git.1.855ef1d.el8 | Fixed | RHBA-2020:2444 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (9)
- http://www.openwall.com/lists/oss-security/2020/03/25/2 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2020-2160 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1819190 Issue Tracking
- https://github.com/advisories/GHSA-c735-g9f2-2mvp Advisory
- https://github.com/jenkinsci/jenkins/commit/f479652171f4ab854747de64b22bf59adb35fb8f
- https://github.com/jenkinsci/jenkins/commit/f7cf28355973df1ca6eb19066370bf70b10742f7
- https://jenkins.io/security/advisory/2020-03-25/#SECURITY-1774 x_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-2160
- https://www.cve.org/CVERecord?id=CVE-2020-2160
| Link | Providers | Tags |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2020/03/25/2 | mailing-listx_refsource_MLISTMailing ListThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2020-2160 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1819190 | Issue Tracking | |
| https://github.com/advisories/GHSA-c735-g9f2-2mvp | Advisory | |
| https://github.com/jenkinsci/jenkins/commit/f479652171f4ab854747de64b22bf59adb35fb8f | ||
| https://github.com/jenkinsci/jenkins/commit/f7cf28355973df1ca6eb19066370bf70b10742f7 | ||
| https://jenkins.io/security/advisory/2020-03-25/#SECURITY-1774 | x_refsource_CONFIRMVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-2160 | ||
| https://www.cve.org/CVERecord?id=CVE-2020-2160 |
Change history (0)
No recorded changes yet.