cbcvebase.
CVE-2024-23903
published 2024-01-24

CVE-2024-23903: Jenkins GitLab Branch Source Plugin 684.vea_fa_7c1e2fe3 and earlier uses a non-constant time comparison function when checking whether the provided and…

medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
Jenkins GitLab Branch Source Plugin 684.vea_fa_7c1e2fe3 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token are equal, potentially allowing attackers to use statistical methods to obtain a valid webhook token.

Affected

13 ranges
VendorProductVersion rangeFixed in
gitlabgitlab
jenkinsgit_server_plugin
jenkinsgithub_branch_source<= 684.vea_fa_7c1e2fe3
jenkinsgitlab_branch_source_plugin
jenkinsjenkins_core
jenkinsjenkins_lts
jenkinsjenkins_uses_the_strict_crumb_issuer_plugin
jenkinsjenkins_weekly
jenkinslog_command_plugin
jenkinsmatrix_project_plugin
jenkinsqualys_policy_compliance_scanning_connector_plugin
jenkinsred_hat_dependency_analytics_plugin
jenkins_projectjenkins_gitlab_branch_source_plugin<= 684.vea_fa_7c1e2fe3