Description
Jenkins Audit Trail Plugin 3.6 and earlier applies pattern matching to a different representation of request URL paths than the Stapler web framework uses for dispatching requests, which allows attackers to craft URLs that bypass request logging of any target URL.
Remediation
References
http://www.openwall.com/lists/oss-security/2020/10/08/5
https://www.jenkins.io/security/advisory/2020-10-08/#SECURITY-1815
Related Vulnerabilities
CVE-2015-5347 Vulnerability in maven package org.apache.wicket:wicket-extensions
CVE-2019-6286 Vulnerability in maven package org.webjars.npm:node-sass
CVE-2022-45598 Vulnerability in npm package @joplin/renderer
CVE-2014-7808 Vulnerability in maven package org.apache.wicket:wicket-util
CVE-2019-10447 Vulnerability in maven package io.jenkins.plugins:sofy-ai