Non-constant Time Comparison Flaw in Jenkins Azure AD Plugin
CVE-2023-41935
7.5HIGH
What is CVE-2023-41935?
The Jenkins Azure AD Plugin, up to version 396.v86ce29279947, is susceptible to a non-constant time comparison issue. This vulnerability arises during the validation of CSRF protection nonces, which can be exploited by attackers employing statistical techniques to deduce a valid nonce from the application. The presence of this flaw underscores the necessity for developers to implement constant-time algorithms for security-critical operations to mitigate potential attacks.
Affected Version(s)
Jenkins Azure AD Plugin 397.v907382dd9b_98
Jenkins Azure AD Plugin 397.v907382dd9b_98
Jenkins Azure AD Plugin 378.380.v545b_1154b_3fb_ < 378.*