Jenkins Use of Insufficiently Random Values Vulnerability - CVE-2020-2099
Jenkins 2.213 and earlier LTS 2.204.1 and earlier improperly reuses encryption key parameters in the Inbound TCP Agent Protocol/3 allowing unauthorized attackers with knowledge of agent names to obtain the connection secrets for those agents which can be used to connect to Jenkins impersonating those agents.