GHSA-rpj6-2q8r-98f8

    Dashboard / Vulnerabilities / GHSA-rpj6-2q8r-98f8

    GHSA-rpj6-2q8r-98f8

    Published: 10 Feb 2022Last Modified: 16 Feb 2024
    Aliases:

    Summary: Request logging bypass in Jenkins Audit Trail Plugin

    Details: Audit Trail Plugin logs requests whose URL path matches an admin-configured regular expression. A discrepancy between the behavior of the plugin and the Stapler web framework in parsing URL paths allows attackers to craft URLs that would bypass request logging in Audit Trail Plugin 3.6 and earlier. This only applies to Jenkins 2.227 and earlier, LTS 2.204.5 and earlier, as the fix for [SECURITY-1774](https://www.jenkins.io/security/advisory/2020-03-25/#SECURITY-1774) prohibits dispatch of affected requests. Audit Trail Plugin 3.7 processes request URL paths the same way as the Stapler web framework.

    Affected packages

    Package

    Name: org.jenkins-ci.plugins:audit-trail

    Purl: pkg:maven/org.jenkins-ci.plugins/audit-trail

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -3.7

    Affected versions

    1.5

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-rpj6-2q8r-98f8 | CVE-DB