Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w7jr-wqw6-54xc

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

Non-constant time comparison of inbound TCP agent connection secret

Jenkins 2.218 and earlier, LTS 2.204.1 and earlier does not use a constant-time comparison validating the connection secret when an inbound TCP agent connection is initiated. This could potentially allow attackers to use statistical methods to obtain the connection secret.

Jenkins 2.219, LTS 2.204.2 now uses a constant-time comparison function for verifying connection secrets.

Пакеты

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

<= 2.204.1

2.204.2

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

>= 2.205, <= 2.218

2.219

EPSS

Процентиль: 82%
0.01645
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-203
CWE-208

Связанные уязвимости

CVSS3: 5.3
redhat
около 6 лет назад

Jenkins 2.218 and earlier, LTS 2.204.1 and earlier did not use a constant-time comparison function for validating connection secrets, which could potentially allow an attacker to use a timing attack to obtain this secret.

CVSS3: 5.3
nvd
около 6 лет назад

Jenkins 2.218 and earlier, LTS 2.204.1 and earlier did not use a constant-time comparison function for validating connection secrets, which could potentially allow an attacker to use a timing attack to obtain this secret.

CVSS3: 5.3
debian
около 6 лет назад

Jenkins 2.218 and earlier, LTS 2.204.1 and earlier did not use a const ...

EPSS

Процентиль: 82%
0.01645
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-203
CWE-208