Description
Jenkins 2.227 and earlier, LTS 2.204.5 and earlier uses different representations of request URL paths, which allows attackers to craft URLs that allow bypassing CSRF protection of any target URL.
Remediation
References
http://www.openwall.com/lists/oss-security/2020/03/25/2
https://jenkins.io/security/advisory/2020-03-25/#SECURITY-1774
Related Vulnerabilities
CVE-2022-21222 Vulnerability in maven package org.webjars.npm:css-what
CVE-2022-36919 Vulnerability in maven package org.jenkins-ci.plugins:coverity
CVE-2013-7285 Vulnerability in maven package com.thoughtworks.xstream:xstream
CVE-2019-1010266 Vulnerability in maven package org.webjars.npm:lodash
CVE-2023-36665 Vulnerability in maven package org.webjars.npm:protobufjs