CVE-2022-36885Observable Discrepancy in Project Jenkins Github Plugin

Severity
5.3MEDIUMNVD
EPSS
0.3%
top 43.34%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 27
Latest updateJul 28

Description

Jenkins GitHub Plugin 1.34.4 and earlier uses a non-constant time comparison function when checking whether the provided and computed webhook signatures are equal, allowing attackers to use statistical methods to obtain a valid webhook signature.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages2 packages

CVEListV5jenkins_project/jenkins_github_pluginunspecified1.34.4
NVDjenkins/github1.34.4

🔴Vulnerability Details

3
OSV
Jenkins GitHub plugin uses weak webhook signature function2022-07-28
GHSA
Jenkins GitHub plugin uses weak webhook signature function2022-07-28
CVEList
CVE-2022-36885: Jenkins GitHub Plugin 12022-07-27

📋Vendor Advisories

2
Jenkins
Jenkins Security Advisory 2022-07-272022-07-27
Red Hat
plugin: Non-constant time webhook signature comparison in GitHub Plugin2022-07-27
CVE-2022-36885 — Observable Discrepancy | cvebase