SB2020013004 - Improper Authentication in Jenkins and LTS



SB2020013004 - Improper Authentication in Jenkins and LTS

Published: January 30, 2020

Security Bulletin ID SB2020013004
Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Improper Authentication (CVE-ID: CVE-2020-2099)

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to the affected software improperly reuses encryption key parameters in the Inbound TCP Agent Protocol/3. A remote attacker with knowledge of agent names can obtain the connection secrets for those agents, which can be used to connect to Jenkins, impersonating those agents.


Remediation

Install update from vendor's website.