Non-Constant Time Comparison Vulnerability in Jenkins Google Login Plugin
CVE-2023-41936

7.5HIGH

Key Information:

Vendor

Jenkins

Vendor
CVE Published:
6 September 2023

What is CVE-2023-41936?

The Jenkins Google Login Plugin versions 1.7 and earlier contain a vulnerability due to the use of a non-constant time comparison function. This flaw may allow attackers to leverage statistical methods to deduce valid tokens by exploiting timing discrepancies when the provided token is compared to the expected token. Such exploitation can potentially lead to unauthorized access and compromise of user accounts. It is crucial for users of this plugin to update to the latest version to mitigate such risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Jenkins Google Login Plugin 0 <= 1.7

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.