cbcvebase.
CVE-2024-23903
published 2024-01-24

CVE-2024-23903: Jenkins GitLab Branch Source Plugin 684.vea_fa_7c1e2fe3 and earlier uses a non-constant time comparison function when checking whether the provided and…

PriorityP425medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
0.50%
39.5th percentile
Jenkins GitLab Branch Source Plugin 684.vea_fa_7c1e2fe3 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token are equal, potentially allowing attackers to use statistical methods to obtain a valid webhook token.

Affected

13 ranges
VendorProductVersion rangeFixed in
gitlabgitlab
jenkinsgit_server_plugin
jenkinsgithub_branch_source<= 684.vea_fa_7c1e2fe3
jenkinsgitlab_branch_source_plugin
jenkinsjenkins_core
jenkinsjenkins_lts
jenkinsjenkins_uses_the_strict_crumb_issuer_plugin
jenkinsjenkins_weekly
jenkinslog_command_plugin
jenkinsmatrix_project_plugin
jenkinsqualys_policy_compliance_scanning_connector_plugin
jenkinsred_hat_dependency_analytics_plugin
jenkins_projectjenkins_gitlab_branch_source_plugin<= 684.vea_fa_7c1e2fe3
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.