cbcvebase.
CVE-2023-41935
published 2023-09-06

CVE-2023-41935: Jenkins Azure AD Plugin 396.v86ce29279947 and earlier, except 378.380.v545b_1154b_3fb_, uses a non-constant time comparison function when checking whether the…

high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
Jenkins Azure AD Plugin 396.v86ce29279947 and earlier, except 378.380.v545b_1154b_3fb_, uses a non-constant time comparison function when checking whether the provided and expected CSRF protection nonce are equal, potentially allowing attackers to use statistical methods to obtain a valid nonce.

Affected

17 ranges
VendorProductVersion rangeFixed in
jenkinsassembla_auth_plugin
jenkinsaws_codecommit_trigger_plugin
jenkinsazure_ad<= 348.vefd011eea_20b
jenkinsazure_ad378.vd6e2874a_69eb – 396.v86ce29279947
jenkinsbitbucket_push_and_pull_request_plugin
jenkinsconfig_file_provider_plugin
jenkinsdisabled_permissions_can_be_granted_by_ssh2_easy_plugin
jenkinsdisabled_permissions_granted_by_assembla_auth_plugin
jenkinsfrugal_testing_plugin
jenkinsgoogle_login_plugin
jenkinsivy_plugin
jenkinsjob_configuration_history_plugin
jenkinsnon-constant_time_token_comparison_in_google_login_plugin
jenkinspipeline_maven_integration_plugin
jenkinsqualys_container_scanning_connector_plugin
jenkinsssh2_easy_plugin
jenkinstap_plugin