Jenkins Use of Insufficiently Random Values Vulnerability - CVE-2020-2099 - Vulnerability Database

Jenkins Use of Insufficiently Random Values Vulnerability - CVE-2020-2099

High
Reference: CVE-2020-2099
Title: Jenkins Use of Insufficiently Random Values Vulnerability
Overview:

Jenkins 2.213 and earlier LTS 2.204.1 and earlier improperly reuses encryption key parameters in the Inbound TCP Agent Protocol/3 allowing unauthorized attackers with knowledge of agent names to obtain the connection secrets for those agents which can be used to connect to Jenkins impersonating those agents.