Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-2218 | Jenkins Tuleap Authentication Plugin 1.1.20 and earlier uses a non-constant time comparison function when validating an authentication token allowing attackers to use statistical methods to obtain a valid authentication token. |
Github GHSA |
GHSA-5r33-mgjf-6656 | Jenkins Tuleap Authentication Plugin non-constant time token comparison |
Tue, 08 Oct 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2024-10-08T18:30:49.930Z
Reserved: 2023-08-14T16:02:56.435Z
Link: CVE-2023-40343
Updated: 2024-08-02T18:31:53.571Z
Status : Modified
Published: 2023-08-16T15:15:11.817
Modified: 2024-11-21T08:19:15.613
Link: CVE-2023-40343
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA