#VU24758 Improper Authentication in Jenkins and Jenkins LTS - CVE-2020-2099
Published: January 30, 2020
Jenkins
Jenkins LTS
Jenkins
Description
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to the affected software improperly reuses encryption key parameters in the Inbound TCP Agent Protocol/3. A remote attacker with knowledge of agent names can obtain the connection secrets for those agents, which can be used to connect to Jenkins, impersonating those agents.