CVE-2022-23106

Related Vulnerabilities: CVE-2022-23106  

Jenkins Configuration as Code Plugin 1.55 and earlier used a non-constant time comparison function when validating an authentication token allowing attackers to use statistical methods to obtain a valid authentication token.

Description

The MITRE CVE dictionary describes this issue as:

Jenkins Configuration as Code Plugin 1.55 and earlier used a non-constant time comparison function when validating an authentication token allowing attackers to use statistical methods to obtain a valid authentication token.

Additional Information

  • Bugzilla 2044462: CVE-2022-23106 jenkins-2-plugins/configuration-as-code: uses a non-constant time comparison function when validating an authentication token
  • CWE-208: Observable Timing Discrepancy
  • FAQ: Frequently asked questions about CVE-2022-23106