Timing Attack Affecting org.jenkins-ci.main:jenkins-core package, versions [,2.204.2) [2.205,2.219)
Threat Intelligence
EPSS
0.2% (59th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-JAVA-ORGJENKINSCIMAIN-3175882
- published 20 Dec 2022
- disclosed 24 May 2022
- credit Jesse Glick, CloudBees, Inc. and, independently, Wasin Saengow
Introduced: 24 May 2022
CVE-2020-2101 Open this link in a new tabHow to fix?
Upgrade org.jenkins-ci.main:jenkins-core
to version 2.204.2, 2.219 or higher.
Overview
org.jenkins-ci.main:jenkins-core is an open source automation server.
Affected versions of this package are vulnerable to Timing Attack due to a missing usage of a constant-time comparison validating for connection secret when an inbound TCP agent connection is initiated. Exploiting this vulnerability allows attackers to use statistical methods to obtain the connection secret.
CVSS Scores
version 3.1