Description
Jenkins Audit Trail Plugin 3.6 and earlier applies pattern matching to a different representation of request URL paths than the Stapler web framework uses for dispatching requests, which allows attackers to craft URLs that bypass request logging of any target URL.
Remediation
References
http://www.openwall.com/lists/oss-security/2020/10/08/5
https://www.jenkins.io/security/advisory/2020-10-08/#SECURITY-1815
Related Vulnerabilities
CVE-2022-23540 Vulnerability in maven package org.webjars.npm:jsonwebtoken
CVE-2013-2165 Vulnerability in maven package org.richfaces.core:richfaces-core-impl
CVE-2022-25940 Vulnerability in npm package lite-server
CVE-2023-49485 Vulnerability in maven package com.jfinal:jfinal
CVE-2020-2187 Vulnerability in maven package org.jenkins-ci.plugins:ec2