In Jenkins Audit Trail Plugin 3.6 and earlier, the default regular expression pattern could be bypassed in many cases by adding a suffix to the URL that would be ignored during request handling.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Audit_trail |
Jenkins |
* |
3.6 (including) |
References