PT-2022-15848 · Jenkins · Jenkins Configuration As Code Plugin+1

James Nord

·

Published

2022-01-12

·

Updated

2023-11-15

·

CVE-2022-23106

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Configuration as Code Plugin versions 1.55 and earlier
Description The issue arises from the use of a non-constant time comparison function when validating an authentication token, allowing attackers to potentially use statistical methods to obtain a valid authentication token. This could enable unauthorized access.
Recommendations For Jenkins Configuration as Code Plugin versions 1.55 and earlier, update to version 1.55.1 or later to resolve the issue. For versions prior to 1.54.1, update to version 1.54.1 or later. For versions prior to 1.53.1, update to version 1.53.1 or later. For versions prior to 1.47.1, update to version 1.47.1 or later.

Exploit

Fix

Side Channel Attack

Weakness Enumeration

Related Identifiers

CVE-2022-23106
GHSA-FPJ7-9XM6-8HGR

Affected Products

Jenkins
Jenkins Configuration As Code Plugin