Token Authentication Flaw in Jenkins Zanata Plugin from Jenkins
CVE-2023-46660
5.3MEDIUM
What is CVE-2023-46660?
The Jenkins Zanata Plugin 0.6 and earlier employs a non-constant time comparison method to verify webhook token hashes. This vulnerability could enable an attacker to exploit statistical methods to derive a valid webhook token, posing significant security risks to applications relying on this plugin. It is crucial for users of affected versions to update to secure their systems against potential exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Jenkins Zanata Plugin 0 <= 0.6
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved