Search Results (Refine Search)
- Keyword (text search): cpe:2.3:a:jenkins:jenkins:2.204.1:*:*:*:lts:*:*:*
- CPE Name Search: true
Vuln ID | Summary | CVSS Severity |
---|---|---|
CVE-2020-2099 |
Jenkins 2.213 and earlier, LTS 2.204.1 and earlier improperly reuses encryption key parameters in the Inbound TCP Agent Protocol/3, allowing unauthorized attackers with knowledge of agent names to obtain the connection secrets for those agents, which can be used to connect to Jenkins, impersonating those agents. Published: January 29, 2020; 11:15:12 AM -0500 |
V4.0:(not available) V3.1: 8.6 HIGH V2.0: 7.5 HIGH |