Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-2522 | Jenkins Azure AD Plugin 396.v86ce29279947 and earlier, except 378.380.v545b_1154b_3fb_, uses a non-constant time comparison function when checking whether the provided and expected CSRF protection nonce are equal, potentially allowing attackers to use statistical methods to obtain a valid nonce. |
Github GHSA |
GHSA-hj7p-h74j-6gxj | Non-constant time nonce comparison in Jenkins Microsoft Entra ID (previously Azure AD) Plugin |
Thu, 26 Sep 2024 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2024-09-26T19:55:15.254Z
Reserved: 2023-09-05T16:39:57.392Z
Link: CVE-2023-41935
Updated: 2024-08-02T19:09:49.440Z
Status : Modified
Published: 2023-09-06T13:15:10.297
Modified: 2024-11-21T08:21:57.173
Link: CVE-2023-41935
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA