jenkins: Inbound TCP Agent Protocol/3 authentication bypass
Published Jan 29, 2020
8.6
HIGHCVSS 3.1
EPSS 1.01%
Description
Jenkins 2.213 and earlier, LTS 2.204.1 and earlier improperly reuses encryption key parameters in the Inbound TCP Agent Protocol/3, allowing unauthorized attackers with knowledge of agent names to obtain the connection secrets for those agents, which can be used to connect to Jenkins, impersonating those agents.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<=2.213
- Version unspecifiedStatusaffectedConstraints<=LTS 2.204.1
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Jenkins project | Jenkins | n/a |
|
No data.
Red Hat OpenShift Container Platform 3.11
atomic-enterprise-service-catalog-1:3.11.170-1.git.1.91db82e.el7
Fixed · RHBA-2020:0402
Red Hat OpenShift Container Platform 3.11
atomic-openshift-0:3.11.170-1.git.0.00cac56.el7
Fixed · RHBA-2020:0402
Red Hat OpenShift Container Platform 3.11
atomic-openshift-cluster-autoscaler-0:3.11.170-1.git.1.0a0df6a.el7
Fixed · RHBA-2020:0402
Red Hat OpenShift Container Platform 3.11
atomic-openshift-descheduler-0:3.11.170-1.git.1.9ad83f2.el7
Fixed · RHBA-2020:0402
Red Hat OpenShift Container Platform 3.11
atomic-openshift-dockerregistry-0:3.11.170-1.git.1.55fab05.el7
Fixed · RHBA-2020:0402
Red Hat OpenShift Container Platform 3.11
atomic-openshift-metrics-server-0:3.11.170-1.git.1.357f177.el7
Fixed · RHBA-2020:0402
Red Hat OpenShift Container Platform 3.11
atomic-openshift-node-problem-detector-0:3.11.170-1.git.1.b1f90a6.el7
Fixed · RHBA-2020:0402
Red Hat OpenShift Container Platform 3.11
atomic-openshift-service-idler-0:3.11.170-1.git.1.8328979.el7
Fixed · RHBA-2020:0402
Red Hat OpenShift Container Platform 3.11
atomic-openshift-web-console-0:3.11.170-1.git.1.3d64e8b.el7
Fixed · RHBA-2020:0402
Red Hat OpenShift Container Platform 3.11
cri-o-0:1.11.16-0.5.dev.rhaos3.11.git3f89eba.el7
Fixed · RHBA-2020:0402
Red Hat OpenShift Container Platform 3.11
golang-github-openshift-oauth-proxy-0:3.11.170-1.git.1.b49be83.el7
Fixed · RHBA-2020:0402
Red Hat OpenShift Container Platform 3.11
golang-github-prometheus-alertmanager-0:3.11.170-1.git.1.61d7960.el7
Fixed · RHBA-2020:0402
Red Hat OpenShift Container Platform 3.11
golang-github-prometheus-node_exporter-0:3.11.170-1.git.1.51473b7.el7
Fixed · RHBA-2020:0402
Red Hat OpenShift Container Platform 3.11
golang-github-prometheus-prometheus-0:3.11.170-1.git.1.227bc98.el7
Fixed · RHBA-2020:0402
Red Hat OpenShift Container Platform 3.11
jenkins-0:2.204.2.1580891656-1.el7
Fixed · RHBA-2020:0402
Red Hat OpenShift Container Platform 3.11
jenkins-2-plugins-0:3.11.1579107288-1.el7
Fixed · RHBA-2020:0402
Red Hat OpenShift Container Platform 3.11
openshift-ansible-0:3.11.170-2.git.5.8802564.el7
Fixed · RHBA-2020:0402
Red Hat OpenShift Container Platform 3.11
openshift-enterprise-autoheal-0:3.11.170-1.git.1.dfe6c52.el7
Fixed · RHBA-2020:0402
Red Hat OpenShift Container Platform 3.11
openshift-enterprise-cluster-capacity-0:3.11.170-1.git.1.661684b.el7
Fixed · RHBA-2020:0402
Red Hat OpenShift Container Platform 3.11
openshift-kuryr-0:3.11.170-1.git.1.7265da1.el7
Fixed · RHBA-2020:0402
Red Hat OpenShift Container Platform 4.3
jenkins-0:2.204.2.1583446818-1.el7
Fixed · RHBA-2020:0675
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Container Platform 3.11 | atomic-enterprise-service-catalog-1:3.11.170-1.git.1.91db82e.el7 | Fixed | RHBA-2020:0402 |
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift-0:3.11.170-1.git.0.00cac56.el7 | Fixed | RHBA-2020:0402 |
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift-cluster-autoscaler-0:3.11.170-1.git.1.0a0df6a.el7 | Fixed | RHBA-2020:0402 |
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift-descheduler-0:3.11.170-1.git.1.9ad83f2.el7 | Fixed | RHBA-2020:0402 |
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift-dockerregistry-0:3.11.170-1.git.1.55fab05.el7 | Fixed | RHBA-2020:0402 |
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift-metrics-server-0:3.11.170-1.git.1.357f177.el7 | Fixed | RHBA-2020:0402 |
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift-node-problem-detector-0:3.11.170-1.git.1.b1f90a6.el7 | Fixed | RHBA-2020:0402 |
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift-service-idler-0:3.11.170-1.git.1.8328979.el7 | Fixed | RHBA-2020:0402 |
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift-web-console-0:3.11.170-1.git.1.3d64e8b.el7 | Fixed | RHBA-2020:0402 |
| Red Hat OpenShift Container Platform 3.11 | cri-o-0:1.11.16-0.5.dev.rhaos3.11.git3f89eba.el7 | Fixed | RHBA-2020:0402 |
| Red Hat OpenShift Container Platform 3.11 | golang-github-openshift-oauth-proxy-0:3.11.170-1.git.1.b49be83.el7 | Fixed | RHBA-2020:0402 |
| Red Hat OpenShift Container Platform 3.11 | golang-github-prometheus-alertmanager-0:3.11.170-1.git.1.61d7960.el7 | Fixed | RHBA-2020:0402 |
| Red Hat OpenShift Container Platform 3.11 | golang-github-prometheus-node_exporter-0:3.11.170-1.git.1.51473b7.el7 | Fixed | RHBA-2020:0402 |
| Red Hat OpenShift Container Platform 3.11 | golang-github-prometheus-prometheus-0:3.11.170-1.git.1.227bc98.el7 | Fixed | RHBA-2020:0402 |
| Red Hat OpenShift Container Platform 3.11 | jenkins-0:2.204.2.1580891656-1.el7 | Fixed | RHBA-2020:0402 |
| Red Hat OpenShift Container Platform 3.11 | jenkins-2-plugins-0:3.11.1579107288-1.el7 | Fixed | RHBA-2020:0402 |
| Red Hat OpenShift Container Platform 3.11 | openshift-ansible-0:3.11.170-2.git.5.8802564.el7 | Fixed | RHBA-2020:0402 |
| Red Hat OpenShift Container Platform 3.11 | openshift-enterprise-autoheal-0:3.11.170-1.git.1.dfe6c52.el7 | Fixed | RHBA-2020:0402 |
| Red Hat OpenShift Container Platform 3.11 | openshift-enterprise-cluster-capacity-0:3.11.170-1.git.1.661684b.el7 | Fixed | RHBA-2020:0402 |
| Red Hat OpenShift Container Platform 3.11 | openshift-kuryr-0:3.11.170-1.git.1.7265da1.el7 | Fixed | RHBA-2020:0402 |
| Red Hat OpenShift Container Platform 4.3 | jenkins-0:2.204.2.1583446818-1.el7 | Fixed | RHBA-2020:0675 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (13)
- http://www.openwall.com/lists/oss-security/2020/01/29/1 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://access.redhat.com/errata/RHBA-2020:0402 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHBA-2020:0675 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2020:0681 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2020:0683 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2020-2099 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1797080 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-5008 Advisory
- https://github.com/advisories/GHSA-qp4f-2w67-c8hw Advisory
- https://github.com/jenkinsci/jenkins/commit/5054bc6e12e1022993d719f66e289ab1d22ae854
- https://jenkins.io/security/advisory/2020-01-29/#SECURITY-1682 x_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-2099
- https://www.cve.org/CVERecord?id=CVE-2020-2099
| Link | Providers | Tags |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2020/01/29/1 | mailing-listx_refsource_MLISTMailing ListThird Party Advisory | |
| https://access.redhat.com/errata/RHBA-2020:0402 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/errata/RHBA-2020:0675 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/errata/RHSA-2020:0681 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/errata/RHSA-2020:0683 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/security/cve/CVE-2020-2099 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1797080 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-5008 | Advisory | |
| https://github.com/advisories/GHSA-qp4f-2w67-c8hw | Advisory | |
| https://github.com/jenkinsci/jenkins/commit/5054bc6e12e1022993d719f66e289ab1d22ae854 | ||
| https://jenkins.io/security/advisory/2020-01-29/#SECURITY-1682 | x_refsource_CONFIRMVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-2099 | ||
| https://www.cve.org/CVERecord?id=CVE-2020-2099 |
Change history (0)
No recorded changes yet.