CVE Published: 06/09/2023 |
CVE Updated: 26/09/2024 |
CVE Year: 2023 Source: jenkins |
Vendor: Jenkins Project |
Product: Jenkins Google Login Plugin Status : PUBLISHED
CVE-2023-41936 Description
Jenkins Google Login Plugin 1.7 and earlier uses a non-constant time comparison function when checking whether the provided and expected token are equal, potentially allowing attackers to use statistical methods to obtain a valid token.