CVE-2023-46657
published 2023-10-25CVE-2023-46657: Jenkins Gogs Plugin 1.0.15 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token are equal…
PriorityP426medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
0.57%
43.7th percentile
Jenkins Gogs Plugin 1.0.15 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token are equal, potentially allowing attackers to use statistical methods to obtain a valid webhook token.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| artifex | mupdf | >= 0 < 1.12.0+ds1-1ubuntu0.1~esm2 | 1.12.0+ds1-1ubuntu0.1~esm2 |
| artifex | mupdf | >= 0 < 1.16.1+ds1-1ubuntu1+esm2 | 1.16.1+ds1-1ubuntu1+esm2 |
| artifex | mupdf | >= 0 < 1.19.0+ds1-2ubuntu0.1~esm1 | 1.19.0+ds1-2ubuntu0.1~esm1 |
| artifex | mupdf | >= 0 < 1.23.10+ds1-1ubuntu0.1~esm1 | 1.23.10+ds1-1ubuntu0.1~esm1 |
| jenkins | cloudbees_cd_plugin | — | — |
| jenkins | edgewall_trac_plugin | — | — |
| jenkins | github_plugin | — | — |
| jenkins | gogs | <= 1.0.15 | — |
| jenkins | gogs_plugin | — | — |
| jenkins | msteams_webhook_trigger_plugin | — | — |
| jenkins | multibranch_scan_webhook_trigger_plugin | — | — |
| jenkins | non-constant_time_webhook_token_comparison_in_gogs_plugin | — | — |
| jenkins | warnings_plugin | — | — |
| jenkins | zanata_plugin | — | — |
| jenkins_project | jenkins_gogs_plugin | <= 1.0.15 | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
osv7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Jenkins
Jenkins Security Advisory 2023-10-25
vendor_jenkins·2023-10-25·CVSS 5.4
CVE-2023-46650 [MEDIUM] Jenkins Security Advisory 2023-10-25
Title: Jenkins Security Advisory 2023-10-25
Jenkins Security Advisory 2023-10-25
Jenkins Security Home
For Administrators
Overview
Terminology
Vulnerabilities and Scoring
Security Advisories
Security Issues
Advisory Schedule
Vulnerabilities in Plugins
How We Fix Security Issues
For Reporters
Reporting Vulnerabilities
Jenkins CNA
For Maintainers
Overview
Vulnerabilities in Plugins
Jenkins Security Team
About
Contributions
This advisory announces vulnerabilities in the following Jenkins deliverables:
CloudBees CD
Plugin
Edgewall Trac
Plugin
GitHub
Plugin
Gogs
Plugin
lambdatest-automation
Plugin
lambdatest-automation
Plugin
MSTeams Webhook Trigger
Plugin
Mult
OSV
mupdf vulnerabilities
osv·2025-11-25·CVSS 7.5
CVE-2023-51103 mupdf vulnerabilities
mupdf vulnerabilities
It was discovered that MuPDF could be made to divide by zero. An attacker
could possibly use this issue to cause a denial of service.
(CVE-2023-51103, CVE-2023-51104, CVE-2023-51105, CVE-2023-51106)
It was discovered that MuPDF incorrectly handled memory under certain
circumstances, which could lead to a NULL pointer dereference. An
attacker could potentially use this issue to cause a denial of service.
(CVE-2024-46657)
It was discovered that MuPDF could enter an infinite recursion when
parsing certain PDF files. An attacker could possibly use this issue to
cause a denial of service. (CVE-2025-46206)
OSV
Jenkins Gogs Plugin uses non-constant time webhook token comparison
osv·2023-10-25
CVE-2023-46657 [LOW] Jenkins Gogs Plugin uses non-constant time webhook token comparison
Jenkins Gogs Plugin uses non-constant time webhook token comparison
Jenkins Gogs Plugin 1.0.15 and earlier does not use a constant-time comparison when checking whether the provided and expected webhook token are equal.
This could potentially allow attackers to use statistical methods to obtain a valid webhook token.
As of publication of this advisory, there is no fix.
GHSA
Jenkins Gogs Plugin uses non-constant time webhook token comparison
ghsa·2023-10-25
CVE-2023-46657 [LOW] CWE-208 Jenkins Gogs Plugin uses non-constant time webhook token comparison
Jenkins Gogs Plugin uses non-constant time webhook token comparison
Jenkins Gogs Plugin 1.0.15 and earlier does not use a constant-time comparison when checking whether the provided and expected webhook token are equal.
This could potentially allow attackers to use statistical methods to obtain a valid webhook token.
As of publication of this advisory, there is no fix.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-10-25
Published