CVE-2022-34174Observable Discrepancy in Project Jenkins

Severity
7.5HIGHNVD
EPSS
0.9%
top 24.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 23
Latest updateJun 24

Description

In Jenkins 2.355 and earlier, LTS 2.332.3 and earlier, an observable timing discrepancy on the login form allows distinguishing between login attempts with an invalid username, and login attempts with a valid username and wrong password, when using the Jenkins user database security realm.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

NVDjenkins/jenkins2.332.3+1
CVEListV5jenkins_project/jenkinsunspecified2.355+1

🔴Vulnerability Details

3
GHSA
Observable timing discrepancy allows determining username validity in Jenkins2022-06-24
OSV
Observable timing discrepancy allows determining username validity in Jenkins2022-06-24
CVEList
CVE-2022-34174: In Jenkins 22022-06-22

📋Vendor Advisories

2
Red Hat
jenkins: Observable timing discrepancy allows determining username validity2022-06-22
Jenkins
Jenkins Security Advisory 2022-06-222022-06-22
CVE-2022-34174 — Observable Discrepancy | cvebase