CVE-2020-2101
Non-constant time comparison of inbound TCP agent connection secret
5.3
MEDIUM
CVSS 3.1
EPSS 1.6%
Description
Jenkins 2.218 and earlier, LTS 2.204.1 and earlier does not use a constant-time comparison validating the connection secret when an inbound TCP agent connection is initiated. This could potentially allow attackers to use statistical methods to obtain the connection secret. Jenkins 2.219, LTS 2.204.2 now uses a constant-time comparison function for verifying connection secrets.
How to fix CVE-2020-2101
To remediate CVE-2020-2101, upgrade the affected package to a fixed version below.
- —upgrade to 2.218.1 or later
- —upgrade to 2.204.2 or later
Is CVE-2020-2101 being exploited?
Low — EPSS is 1.6%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 2.218.1
- from 0, < 2.204.2
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.3 | CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N |