Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qp4f-2w67-c8hw

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.6

Описание

Inbound TCP Agent Protocol/3 authentication bypass in Jenkins

Jenkins 2.213 and earlier, LTS 2.204.1 and earlier includes support for the Inbound TCP Agent Protocol/3 for communication between controller and agents. While this protocol has been deprecated in 2018 and was recently removed from Jenkins in 2.214, it could still easily be enabled in Jenkins LTS 2.204.1, 2.213, and older.

This protocol incorrectly reuses encryption parameters which allow an unauthenticated remote attacker to determine the connection secret. This secret can then be used to connect attacker-controlled Jenkins agents to the Jenkins controller.

Jenkins 2.204.2 no longer allows for the use of Inbound TCP Agent Protocol/3 by default. The system property jenkins.slaves.JnlpSlaveAgentProtocol3.ALLOW_UNSAFE can be set to true to allow enabling the Inbound TCP Agent Protocol/3 in Jenkins 2.204.2, but doing so is strongly discouraged.

Inbound TCP Agent Protocol/3 was removed completely from Jenkins 2.214 and will not be part of Jenkins LTS after the end of the 2.204.x line.

Пакеты

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

< 2.204.2

2.204.2

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

>= 2.205, < 2.214

2.214

EPSS

Процентиль: 70%
0.00643
Низкий

8.6 High

CVSS3

Дефекты

CWE-323
CWE-330

Связанные уязвимости

CVSS3: 8.6
redhat
около 6 лет назад

Jenkins 2.213 and earlier, LTS 2.204.1 and earlier improperly reuses encryption key parameters in the Inbound TCP Agent Protocol/3, allowing unauthorized attackers with knowledge of agent names to obtain the connection secrets for those agents, which can be used to connect to Jenkins, impersonating those agents.

CVSS3: 8.6
nvd
около 6 лет назад

Jenkins 2.213 and earlier, LTS 2.204.1 and earlier improperly reuses encryption key parameters in the Inbound TCP Agent Protocol/3, allowing unauthorized attackers with knowledge of agent names to obtain the connection secrets for those agents, which can be used to connect to Jenkins, impersonating those agents.

CVSS3: 8.6
debian
около 6 лет назад

Jenkins 2.213 and earlier, LTS 2.204.1 and earlier improperly reuses e ...

EPSS

Процентиль: 70%
0.00643
Низкий

8.6 High

CVSS3

Дефекты

CWE-323
CWE-330