CVE-2020-2160
HIGHCVSS 8.8/10EPSS 1.99%
Last modified
CVE-2020-2160 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Jenkins 2.227 and earlier, LTS 2.204.5 and earlier uses different representations of request URL paths, which allows attackers to craft URLs that allow bypassing CSRF protection of any target URL.. EPSS estimates a 1.99% chance of exploitation in the next 30 days.
Description
Jenkins 2.227 and earlier, LTS 2.204.5 and earlier uses different representations of request URL paths, which allows attackers to craft URLs that allow bypassing CSRF protection of any target URL.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Jenkins | Jenkins | <= 2.204.5 |
| Jenkins | Jenkins | <= 2.227 |
References
- http://www.openwall.com/lists/oss-security/2020/03/25/2Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2020/03/25/2Mailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-2160?
Jenkins 2.227 and earlier, LTS 2.204.5 and earlier uses different representations of request URL paths, which allows attackers to craft URLs that allow bypassing CSRF protection of any target URL.
How severe is CVE-2020-2160?
CVE-2020-2160 has a CVSS score of 8.8/10 (HIGH severity). The EPSS model estimates a 1.99% probability of exploitation in the next 30 days.
How do I fix CVE-2020-2160?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-21594libde265 v1.0.4 contains a heap buffer overflow in the put_e…6.5
- CVE-2020-21595libde265 v1.0.4 contains a heap buffer overflow in the mc_lu…6.5
- CVE-2020-21596libde265 v1.0.4 contains a global buffer overflow in the dec…6.5
- CVE-2020-21597libde265 v1.0.4 contains a heap buffer overflow in the mc_ch…6.5
- CVE-2020-21598libde265 v1.0.4 contains a heap buffer overflow in the ff_he…8.8
- CVE-2020-21599libde265 v1.0.4 contains a heap buffer overflow in the de265…6.5
- CVE-2020-21600libde265 v1.0.4 contains a heap buffer overflow in the put_w…6.5
- CVE-2020-21601libde265 v1.0.4 contains a stack buffer overflow in the put_…6.5
- CVE-2020-21602libde265 v1.0.4 contains a heap buffer overflow in the put_w…6.5
- CVE-2020-21603libde265 v1.0.4 contains a heap buffer overflow in the put_q…6.5
- CVE-2020-21604libde265 v1.0.4 contains a heap buffer overflow fault in the…6.5
- CVE-2020-21605libde265 v1.0.4 contains a segmentation fault in the apply_s…6.5
Are you affected by CVE-2020-2160?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
