#VU24758 Improper Authentication in Jenkins and Jenkins LTS - CVE-2020-2099

 

#VU24758 Improper Authentication in Jenkins and Jenkins LTS - CVE-2020-2099

Published: January 30, 2020


Vulnerability identifier: #VU24758
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2020-2099
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Jenkins
Jenkins LTS
Software vendor:
Jenkins

Description

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to the affected software improperly reuses encryption key parameters in the Inbound TCP Agent Protocol/3. A remote attacker with knowledge of agent names can obtain the connection secrets for those agents, which can be used to connect to Jenkins, impersonating those agents.


Remediation

Install updates from vendor's website.

External links