#VU24760 Information disclosure in Jenkins and Jenkins LTS - CVE-2020-2101
Published: January 30, 2020
Jenkins
Jenkins LTS
Jenkins
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to the affected software does not use a constant-time comparison validating the connection secret when an inbound TCP agent connection is initiated. A remote authenticated attacker can use statistical methods to obtain the connection secret.