cbcvebase.
CVE-2020-2099
published 2020-01-29

CVE-2020-2099: Jenkins 2.213 and earlier, LTS 2.204.1 and earlier improperly reuses encryption key parameters in the Inbound TCP Agent Protocol/3, allowing unauthorized…

high8.6CVSS 3.1
AVNACLPRNUINSUCHILAL
Jenkins 2.213 and earlier, LTS 2.204.1 and earlier improperly reuses encryption key parameters in the Inbound TCP Agent Protocol/3, allowing unauthorized attackers with knowledge of agent names to obtain the connection secrets for those agents, which can be used to connect to Jenkins, impersonating those agents.

Affected

9 ranges
VendorProductVersion rangeFixed in
jenkinscode_coverage_plugin
jenkinsfortify_plugin
jenkinsjenkins<= 2.204.1
jenkinsjenkins<= 2.218
jenkinsjenkins_core
jenkinsjenkins_lts
jenkinsjenkins_weekly
jenkinswebsphere_deployer_plugin
jenkins_projectjenkinsunspecified – 2.213