CVE-2020-2101 PUBLISHED

Jenkins 2.218 and earlier, LTS 2.204.1 and earlier did not use a constant-time comparison function for validating connection secrets, which could potentially allow an attacker to use a timing attack to obtain this secret.

EPSS 1.65% · 81.9th percentile

Risk Scores

EPSS Score
1.65%
81.9th percentile

Affected Products

VendorProductVersions
Bitnamijenkins0
Bitnamijenkins0

Timeline

References

Open in Interactive Console →