Jenkins 2.218 and earlier, LTS 2.204.1 and earlier used a non-constant time comparison function when validating an HMAC.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-3793 Jenkins 2.218 and earlier, LTS 2.204.1 and earlier used a non-constant time comparison function when validating an HMAC.
Github GHSA Github GHSA GHSA-fj6f-6933-839j Non-constant time HMAC comparison
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published:

Updated: 2024-08-04T07:01:39.728Z

Reserved: 2019-12-05T00:00:00

Link: CVE-2020-2102

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-01-29T16:15:12.303

Modified: 2024-11-21T05:24:37.823

Link: CVE-2020-2102

cve-icon Redhat

Severity : Moderate

Publid Date: 2020-01-29T00:00:00Z

Links: CVE-2020-2102 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses