Jenkins 2.218 and earlier, LTS 2.204.1 and earlier used a non-constant time comparison function when validating an HMAC.
2020-01-29T16:15:12.303
2024-11-21T05:24:37.823
Modified
CVSSv3.1: 5.3 (MEDIUM)
AV:N/AC:M/Au:S/C:P/I:N/A:N
6.8
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | jenkins | jenkins | ≤ 2.204.1 | Yes |
| Application | jenkins | jenkins | ≤ 2.218 | Yes |