CVE Published: 06/09/2023 |
CVE Updated: 26/09/2024 |
CVE Year: 2023 Source: jenkins |
Vendor: Jenkins Project |
Product: Jenkins Azure AD Plugin Status : PUBLISHED
CVE-2023-41935 Description
Jenkins Azure AD Plugin 396.v86ce29279947 and earlier, except 378.380.v545b_1154b_3fb_, uses a non-constant time comparison function when checking whether the provided and expected CSRF protection nonce are equal, potentially allowing attackers to use statistical methods to obtain a valid nonce.