VDB
CVE-2020-2103
CVE-2020-2103
PUBLISHED
Jenkins 2.218 and earlier, LTS 2.204.1 and earlier exposed session identifiers on a user's detail object in the whoAmI diagnostic page.
EPSS 45.21% · 97.7th percentile
Risk Scores
EPSS Score
45.21%
97.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | jenkins | 0 |
| Bitnami | jenkins | 0 |
Exploit Intelligence
- https://jenkins.io/security/advisory/2020-01-29/#SECURITY-1695 (circl)
- [oss-security] 20200129 Multiple vulnerabilities in Jenkins and Jenkins plugins (circl)
- RHSA-2020:0681 (circl)
- RHSA-2020:0683 (circl)
- RHBA-2020:0402 (circl)
- RHBA-2020:0675 (circl)
- web_poc_map_v2.yaml (github-poc)
- web_poc_map_v2.yaml (github-poc)
- web_poc_map_v2.yaml (github-poc)
- web_poc_map_v2.yaml (github-poc)
…and 9 more exploits
Timeline
- Jan 29, 2020 CVE Published
- Mar 17, 2020 CVE Updated
- Apr 14, 2021 EPSS Score
- Feb 4, 2022 EPSS Score
- Mar 5, 2022 EPSS Score
- Sep 22, 2023 EPSS Score
- Dec 17, 2024 EPSS Score
- Jan 22, 2025 EPSS Score
- Mar 18, 2025 EPSS Score
- Mar 24, 2025 EPSS Score
- Mar 26, 2025 EPSS Score
- Mar 29, 2025 EPSS Score
References
- http://www.openwall.com/lists/oss-security/2020/01/29/1 url
- https://access.redhat.com/errata/RHBA-2020:0402 url
- https://access.redhat.com/errata/RHBA-2020:0675 url
- https://access.redhat.com/errata/RHSA-2020:0681 url
- https://access.redhat.com/errata/RHSA-2020:0683 url
- https://jenkins.io/security/advisory/2020-01-29/#SECURITY-1695 url
- https://nvd.nist.gov/vuln/detail/CVE-2020-2103 url