Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9grj-j43m-mjqr

Опубликовано: 24 июн. 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

Observable timing discrepancy allows determining username validity in Jenkins

In Jenkins 2.355 and earlier, LTS 2.332.3 and earlier, an observable timing discrepancy on the login form allows distinguishing between login attempts with an invalid username, and login attempts with a valid username and wrong password, when using the Jenkins user database security realm. This allows attackers to determine the validity of attacker-specified usernames.

Login attempts with an invalid username now validate a synthetic password to eliminate the timing discrepancy in Jenkins 2.356, LTS 2.332.4.

Пакеты

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

>= 2.334, < 2.356

2.356

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

< 2.332.4

2.332.4

EPSS

Процентиль: 83%
0.01929
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-203
CWE-208

Связанные уязвимости

CVSS3: 7.5
redhat
больше 3 лет назад

In Jenkins 2.355 and earlier, LTS 2.332.3 and earlier, an observable timing discrepancy on the login form allows distinguishing between login attempts with an invalid username, and login attempts with a valid username and wrong password, when using the Jenkins user database security realm.

CVSS3: 7.5
nvd
больше 3 лет назад

In Jenkins 2.355 and earlier, LTS 2.332.3 and earlier, an observable timing discrepancy on the login form allows distinguishing between login attempts with an invalid username, and login attempts with a valid username and wrong password, when using the Jenkins user database security realm.

CVSS3: 7.5
debian
больше 3 лет назад

In Jenkins 2.355 and earlier, LTS 2.332.3 and earlier, an observable t ...

EPSS

Процентиль: 83%
0.01929
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-203
CWE-208