Improper Authentication in Jenkins and Jenkins LTS - CVE-2020-2099

 

Improper Authentication in Jenkins and Jenkins LTS - CVE-2020-2099

Published: January 30, 2020


Vulnerability identifier: #VU24758
CSH Severity: High
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-2099
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to the affected software improperly reuses encryption key parameters in the Inbound TCP Agent Protocol/3. A remote attacker with knowledge of agent names can obtain the connection secrets for those agents, which can be used to connect to Jenkins, impersonating those agents.


Affected software

Jenkins
Jenkins LTS
skopeo (Red Hat package)
runc (Red Hat package)
buildah (Red Hat package)
cri-o (Red Hat package)
cri-tools (Red Hat package)
ovn2.12 (Red Hat package)
jenkins (Red Hat package)
openshift (Red Hat package)
openshift-ansible (Red Hat package)
openshift-clients (Red Hat package)
atomic-enterprise-service-catalog (Red Hat package)
machine-config-daemon (Red Hat package)
openshift-kuryr (Red Hat package)
atomic-openshift-service-idler (Red Hat package)
jenkins-2-plugins (Red Hat package)
Red Hat OpenShift Container Platform

How to mitigate CVE-2020-2099

Install updates from vendor's website.

Jenkins - update to 2.214
Jenkins LTS - update to 2.204.2
skopeo (Red Hat package) - update to 0.1.40-4.rhaos.el8
runc (Red Hat package) - update to 1.0.0-65.rc10.rhaos4.3.el8
buildah (Red Hat package) - update to 1.11.6-4.el8
cri-o (Red Hat package) - update to 1.16.3-22.dev.rhaos4.3.git11c04e3.el8
cri-tools (Red Hat package) - addressed in versions 1.17.0-1.el7, 1.17.0-2.el8
ovn2.12 (Red Hat package) - update to 2.12.0-32.el7fdn
jenkins (Red Hat package) - update to 2.204.2.1583446818-1.el7
Red Hat OpenShift Container Platform - update to 4.3.5
openshift (Red Hat package) - addressed in versions 4.3.5-202002280657.git.0.b3bfb5a.el7, 4.3.5-202002280657.git.0.b3bfb5a.el8
openshift-ansible (Red Hat package) - update to 4.3.5-202002280657.git.1.e4f02b3.el7
openshift-clients (Red Hat package) - addressed in versions 4.3.5-202002280657.git.1.55a9334.el7, 4.3.5-202002280657.git.1.55a9334.el8
atomic-enterprise-service-catalog (Red Hat package) - update to 4.3.5-202003020117.git.0.4eb885c.el7
machine-config-daemon (Red Hat package) - update to 4.3.5-202003020117.git.0.61e0e48.el8
openshift-kuryr (Red Hat package) - update to 4.3.5-202003020117.git.0.237579a.el8
atomic-openshift-service-idler (Red Hat package) - update to 4.3.5-202003020117.git.13.3ac2b0e.el7
jenkins-2-plugins (Red Hat package) - update to 4.3.1583445947-1.el7

External References

Related Security Bulletins