Show plain JSON{"affected_release": [{"advisory": "RHBA-2020:2477", "cpe": "cpe:/a:redhat:openshift:3.11::el7", "package": "jenkins-0:2.222.1.1591351669-1.el7", "product_name": "Red Hat OpenShift Container Platform 3.11", "release_date": "2020-06-17T00:00:00Z"}, {"advisory": "RHBA-2020:2435", "cpe": "cpe:/a:redhat:openshift:4.3::el7", "package": "atomic-enterprise-service-catalog-1:4.3.25-202006081518.git.1.52b3a66.el7", "product_name": "Red Hat OpenShift Container Platform 4.3", "release_date": "2020-06-17T00:00:00Z"}, {"advisory": "RHBA-2020:2435", "cpe": "cpe:/a:redhat:openshift:4.3::el7", "package": "atomic-openshift-service-idler-0:4.3.25-202006081518.git.1.79365c5.el7", "product_name": "Red Hat OpenShift Container Platform 4.3", "release_date": "2020-06-17T00:00:00Z"}, {"advisory": "RHBA-2020:2435", "cpe": "cpe:/a:redhat:openshift:4.3::el7", "package": "conmon-2:2.0.17-1.rhaos4.3.el8", "product_name": "Red Hat OpenShift Container Platform 4.3", "release_date": "2020-06-17T00:00:00Z"}, {"advisory": "RHBA-2020:2435", "cpe": "cpe:/a:redhat:openshift:4.3::el7", "package": "cri-o-0:1.16.6-15.dev.rhaos4.3.gitebc053b.el7", "product_name": "Red Hat OpenShift Container Platform 4.3", "release_date": "2020-06-17T00:00:00Z"}, {"advisory": "RHBA-2020:2435", "cpe": "cpe:/a:redhat:openshift:4.3::el7", "package": "jenkins-0:2.222.1.1591349991-1.el7", "product_name": "Red Hat OpenShift Container Platform 4.3", "release_date": "2020-06-17T00:00:00Z"}, {"advisory": "RHBA-2020:2435", "cpe": "cpe:/a:redhat:openshift:4.3::el7", "package": "machine-config-daemon-0:4.3.25-202006081518.git.1.478b31a.el8", "product_name": "Red Hat OpenShift Container Platform 4.3", "release_date": "2020-06-17T00:00:00Z"}, {"advisory": "RHBA-2020:2435", "cpe": "cpe:/a:redhat:openshift:4.3::el7", "package": "openshift-0:4.3.25-202006060952.git.1.96c30f6.el8", "product_name": "Red Hat OpenShift Container Platform 4.3", "release_date": "2020-06-17T00:00:00Z"}, {"advisory": "RHBA-2020:2435", "cpe": "cpe:/a:redhat:openshift:4.3::el7", "package": "openshift-ansible-0:4.3.25-202006060952.git.1.1253fde.el7", "product_name": "Red Hat OpenShift Container Platform 4.3", "release_date": "2020-06-17T00:00:00Z"}, {"advisory": "RHBA-2020:2435", "cpe": "cpe:/a:redhat:openshift:4.3::el7", "package": "openshift-clients-0:4.3.25-202006060952.git.1.fd93102.el7", "product_name": "Red Hat OpenShift Container Platform 4.3", "release_date": "2020-06-17T00:00:00Z"}, {"advisory": "RHBA-2020:2435", "cpe": "cpe:/a:redhat:openshift:4.3::el7", "package": "openshift-kuryr-0:4.3.25-202006081518.git.1.240b401.el8", "product_name": "Red Hat OpenShift Container Platform 4.3", "release_date": "2020-06-17T00:00:00Z"}, {"advisory": "RHBA-2020:2435", "cpe": "cpe:/a:redhat:openshift:4.3::el7", "package": "s390utils-2:2.6.0-23.el8", "product_name": "Red Hat OpenShift Container Platform 4.3", "release_date": "2020-06-17T00:00:00Z"}, {"advisory": "RHBA-2020:2444", "cpe": "cpe:/a:redhat:openshift:4.4::el7", "package": "atomic-enterprise-service-catalog-1:4.4.0-202006080017.git.1.77a5cc9.el7", "product_name": "Red Hat OpenShift Container Platform 4.4", "release_date": "2020-06-17T00:00:00Z"}, {"advisory": "RHBA-2020:2444", "cpe": "cpe:/a:redhat:openshift:4.4::el7", "package": "atomic-openshift-service-idler-0:4.4.0-202006080017.git.1.7e463c3.el7", "product_name": "Red Hat OpenShift Container Platform 4.4", "release_date": "2020-06-17T00:00:00Z"}, {"advisory": "RHBA-2020:2444", "cpe": "cpe:/a:redhat:openshift:4.4::el7", "package": "conmon-2:2.0.17-1.rhaos4.4.el8", "product_name": "Red Hat OpenShift Container Platform 4.4", "release_date": "2020-06-17T00:00:00Z"}, {"advisory": "RHBA-2020:2444", "cpe": "cpe:/a:redhat:openshift:4.4::el7", "package": "cri-o-0:1.17.4-14.dev.rhaos4.4.gitb93af5d.el7", "product_name": "Red Hat OpenShift Container Platform 4.4", "release_date": "2020-06-17T00:00:00Z"}, {"advisory": "RHBA-2020:2444", "cpe": "cpe:/a:redhat:openshift:4.4::el7", "package": "jenkins-0:2.222.1.1591351066-1.el7", "product_name": "Red Hat OpenShift Container Platform 4.4", "release_date": "2020-06-17T00:00:00Z"}, {"advisory": "RHBA-2020:2444", "cpe": "cpe:/a:redhat:openshift:4.4::el7", "package": "machine-config-daemon-0:4.4.0-202006080017.git.1.32e0736.el8", "product_name": "Red Hat OpenShift Container Platform 4.4", "release_date": "2020-06-17T00:00:00Z"}, {"advisory": "RHBA-2020:2444", "cpe": "cpe:/a:redhat:openshift:4.4::el7", "package": "openshift-0:4.4.0-202006061254.git.1.dc84fb4.el8", "product_name": "Red Hat OpenShift Container Platform 4.4", "release_date": "2020-06-17T00:00:00Z"}, {"advisory": "RHBA-2020:2444", "cpe": "cpe:/a:redhat:openshift:4.4::el7", "package": "openshift-ansible-0:4.4.0-202006061254.git.1.a996454.el7", "product_name": "Red Hat OpenShift Container Platform 4.4", "release_date": "2020-06-17T00:00:00Z"}, {"advisory": "RHBA-2020:2444", "cpe": "cpe:/a:redhat:openshift:4.4::el7", "package": "openshift-clients-0:4.4.0-202006061254.git.1.26cb6dc.el7", "product_name": "Red Hat OpenShift Container Platform 4.4", "release_date": "2020-06-17T00:00:00Z"}, {"advisory": "RHBA-2020:2444", "cpe": "cpe:/a:redhat:openshift:4.4::el7", "package": "openshift-kuryr-0:4.4.0-202006080017.git.1.855ef1d.el8", "product_name": "Red Hat OpenShift Container Platform 4.4", "release_date": "2020-06-17T00:00:00Z"}], "bugzilla": {"description": "jenkins: CSRF protection bypass via crafted URLs", "id": "1819190", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1819190"}, "csaw": false, "cvss3": {"cvss3_base_score": "8.8", "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "status": "verified"}, "cwe": "CWE-352", "details": ["Jenkins 2.227 and earlier, LTS 2.204.5 and earlier uses different representations of request URL paths, which allows attackers to craft URLs that allow bypassing CSRF protection of any target URL."], "name": "CVE-2020-2160", "public_date": "2020-03-25T00:00:00Z", "references": ["https://www.cve.org/CVERecord?id=CVE-2020-2160\nhttps://nvd.nist.gov/vuln/detail/CVE-2020-2160\nhttps://jenkins.io/security/advisory/2020-03-25/#SECURITY-1774"], "threat_severity": "Important"}