Description
In Jenkins 2.355 and earlier, LTS 2.332.3 and earlier, an observable timing discrepancy on the login form allows distinguishing between login attempts with an invalid username, and login attempts with a valid username and wrong password, when using the Jenkins user database security realm.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-6009 | In Jenkins 2.355 and earlier, LTS 2.332.3 and earlier, an observable timing discrepancy on the login form allows distinguishing between login attempts with an invalid username, and login attempts with a valid username and wrong password, when using the Jenkins user database security realm. |
Github GHSA |
GHSA-9grj-j43m-mjqr | Observable timing discrepancy allows determining username validity in Jenkins |
References
History
No history.
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2024-08-03T08:16:17.136Z
Reserved: 2022-06-21T00:00:00.000Z
Link: CVE-2022-34174
No data.
Status : Modified
Published: 2022-06-23T17:15:15.507
Modified: 2024-11-21T07:09:00.193
Link: CVE-2022-34174
OpenCVE Enrichment
No data.
EUVD
Github GHSA