CVE Published: 12/01/2022 |
CVE Updated: 03/08/2024 |
CVE Year: 2022 Source: jenkins |
Vendor: Jenkins project |
Product: Jenkins Configuration as Code Plugin Status : PUBLISHED
CVE-2022-23106 Description
Jenkins Configuration as Code Plugin 1.55 and earlier used a non-constant time comparison function when validating an authentication token allowing attackers to use statistical methods to obtain a valid authentication token.