Severity
5.8MEDIUMNVD
EPSS
1.4%
top 19.76%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 29
Latest updateMay 24

Description

Jenkins 2.218 and earlier, LTS 2.204.1 and earlier was vulnerable to a UDP amplification reflection denial of service attack on port 33848.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:LExploitability: 3.9 | Impact: 1.4

Affected Packages2 packages

NVDjenkins/jenkins2.204.1+1
CVEListV5jenkins_project/jenkinsunspecified2.218+1

🔴Vulnerability Details

3
GHSA
Jenkins vulnerable to UDP amplification reflection attack2022-05-24
OSV
Jenkins vulnerable to UDP amplification reflection attack2022-05-24
CVEList
CVE-2020-2100: Jenkins 22020-01-29

📋Vendor Advisories

5
Cisco
Cisco Firepower 2100 Series SSL/TLS Inspection Denial of Service Vulnerability2020-10-21
Cisco
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software for Firepower 1000/2100 Series Appliances Secure Boot Bypass Vulnerabilities2020-10-21
Cisco
Cisco Firepower 2100 Series Security Appliances ARP Denial of Service Vulnerability2020-05-06
Jenkins
Jenkins Security Advisory 2020-01-292020-01-29
Red Hat
jenkins: UDP multicast/broadcast service amplification reflection attack2020-01-29

🕵️Threat Intelligence

1
Wiz
CVE-2020-37140 Impact, Exploitability, and Mitigation Steps | Wiz

💬Community

2
Bugzilla
CVE-2020-2100 jenkins: UDP multicast/broadcast service amplification reflection attack [fedora-all]2020-01-31
Bugzilla
CVE-2020-2100 jenkins: UDP multicast/broadcast service amplification reflection attack2020-01-31
CVE-2020-2100 — Jenkins Project Jenkins vulnerability | cvebase