CVE-2020-2099
Inbound TCP Agent Protocol/3 authentication bypass in Jenkins
8.6
HIGH
CVSS 3.1
EPSS 1.0%
Description
Jenkins 2.213 and earlier, LTS 2.204.1 and earlier improperly reuses encryption key parameters in the Inbound TCP Agent Protocol/3, allowing unauthorized attackers with knowledge of agent names to obtain the connection secrets for those agents, which can be used to connect to Jenkins, impersonating those agents.
How to fix CVE-2020-2099
To remediate CVE-2020-2099, upgrade the affected package to a fixed version below.
- —upgrade to 2.218.1 or later
- —upgrade to 2.204.2 or later
Is CVE-2020-2099 being exploited?
Low — EPSS is 1.0%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 2.218.1
- from 0, < 2.204.2
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.6 | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L |