5.3
CVSSv3

CVE-2024-23903

Published: 24/01/2024 Updated: 31/01/2024
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Jenkins GitLab Branch Source Plugin 684.vea_fa_7c1e2fe3 and previous versions uses a non-constant time comparison function when checking whether the provided and expected webhook token are equal, potentially allowing malicious users to use statistical methods to obtain a valid webhook token.

Vulnerable Product Search on Vulmon Subscribe to Product

jenkins github branch source

Mailing Lists

Jenkins is an open source automation server which enables developers around the world to reliably build, test, and deploy their software The following releases contain fixes for security vulnerabilities: * Jenkins 2442 * Jenkins LTS 24263 * Git server Plugin 99101v720e86326c09 * GitLab Branch Source Plugin 688v5fa_356ee8520 * Matrix Projec ...