CVE-2022-36885

CVSS v3.1 5.3 (Medium)
53% Progress
EPSS 0.08 % (34th)
0.08% Progress
Affected Products 1
Advisories 2

Jenkins GitHub Plugin 1.34.4 and earlier uses a non-constant time comparison function when checking whether the provided and computed webhook signatures are equal, allowing attackers to use statistical methods to obtain a valid webhook signature.

Weaknesses
CWE-203
Observable Discrepancy
CVE Status
PUBLISHED
CNA
Jenkins Project
Published Date
2022-07-27 15:15:08
(2 years ago)
Updated Date
2023-11-22 21:11:43
(10 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Jenkins Github for Jenkins 1.34.4 and prior versions cpe:2.3:a:jenkins:github::*:*:*:*:jenkins <= 1.34.4
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...