[MAVEN:GHSA-G58X-57FV-86JH] Jenkins Google Login Plugin non-constant time token comparison

Severity High
Affected Packages 1
Fixed Packages 1
CVEs 1

Jenkins Google Login Plugin 1.7 and earlier uses a non-constant time comparison function when checking whether the provided and expected token are equal, potentially allowing attackers to use statistical methods to obtain a valid token.

Package Affected Version
pkg:maven/org.jenkins-ci.plugins/google-login <= 1.7
ID
MAVEN:GHSA-G58X-57FV-86JH
Severity
high
URL
https://github.com/advisories/GHSA-g58x-57fv-86jh
Published
2023-09-06T15:30:26
(12 months ago)
Modified
2024-01-09T18:41:01
(8 months ago)
Rights
Maven Security Team
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.jenkins-ci.plugins/google-login org.jenkins-ci.plugins google-login <= 1.7
Fixed pkg:maven/org.jenkins-ci.plugins/google-login org.jenkins-ci.plugins google-login = 1.8
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...