Jenkins 2.227 and earlier, LTS 2.204.5 and earlier uses different representations of request URL paths, which allows attackers to craft URLs that allow bypassing CSRF protection of any target URL.
| Software | From | Fixed in |
|---|---|---|
| jenkins / jenkins | - | 2.204.5.x |
| jenkins / jenkins | - | 2.227.x |
org.jenkins-ci.main / jenkins-core
|
- | 2.228 |
org.jenkins-ci.main / jenkins-core
|
2.204.6 | 2.228 |