Description
Jenkins 2.227 and earlier, LTS 2.204.5 and earlier uses different representations of request URL paths, which allows attackers to craft URLs that allow bypassing CSRF protection of any target URL.
Remediation
References
http://www.openwall.com/lists/oss-security/2020/03/25/2
https://jenkins.io/security/advisory/2020-03-25/#SECURITY-1774
Related Vulnerabilities
CVE-2018-1002204 Vulnerability in maven package org.webjars:adm-zip
CVE-2022-41404 Vulnerability in maven package org.ini4j:ini4j
CVE-2021-21633 Vulnerability in maven package org.jenkins-ci.plugins:dependency-track
CVE-2023-46493 Vulnerability in npm package @evershop/evershop
CVE-2018-20190 Vulnerability in maven package org.webjars.npm:node-sass