SB2020013004 - Improper Authentication in Jenkins and LTS
Published: January 30, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper Authentication (CVE-ID: CVE-2020-2099)
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to the affected software improperly reuses encryption key parameters in the Inbound TCP Agent Protocol/3. A remote attacker with knowledge of agent names can obtain the connection secrets for those agents, which can be used to connect to Jenkins, impersonating those agents.
Remediation
Install update from vendor's website.