CVE Database
/

CVE-2020-2099

Back to search

CVE-2020-2099

Published: Jan 29, 2020

Modified: Aug 4, 2024

PUBLISHED

Description

Jenkins 2.213 and earlier, LTS 2.204.1 and earlier improperly reuses encryption key parameters in the Inbound TCP Agent Protocol/3, allowing unauthorized attackers with knowledge of agent names to obtain the connection secrets for those agents, which can be used to connect to Jenkins, impersonating those agents.

VendorProductVersions

Jenkins project

Jenkins

affected
unspecified - <= 2.213
affected
unspecified - <= LTS 2.204.1

References

RHSA-2020:0681
vendor-advisory
x_refsource_REDHAT
RHSA-2020:0683
vendor-advisory
x_refsource_REDHAT
RHBA-2020:0402
vendor-advisory
x_refsource_REDHAT
RHBA-2020:0675
vendor-advisory
x_refsource_REDHAT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now
CVE-2020-2099 - Security Vulnerability | QwikSec