Non-Constant Time Comparison Vulnerability in Jenkins Google Login Plugin
CVE-2023-41936
7.5HIGH
What is CVE-2023-41936?
The Jenkins Google Login Plugin versions 1.7 and earlier contain a vulnerability due to the use of a non-constant time comparison function. This flaw may allow attackers to leverage statistical methods to deduce valid tokens by exploiting timing discrepancies when the provided token is compared to the expected token. Such exploitation can potentially lead to unauthorized access and compromise of user accounts. It is crucial for users of this plugin to update to the latest version to mitigate such risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Jenkins Google Login Plugin 0 <= 1.7
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved