CVE Database
/

CVE-2023-41935

Back to search

CVE-2023-41935

Published: Sep 6, 2023

Modified: Sep 26, 2024

PUBLISHED

Description

Jenkins Azure AD Plugin 396.v86ce29279947 and earlier, except 378.380.v545b_1154b_3fb_, uses a non-constant time comparison function when checking whether the provided and expected CSRF protection nonce are equal, potentially allowing attackers to use statistical methods to obtain a valid nonce.

VendorProductVersions

Jenkins Project

Jenkins Azure AD Plugin

unaffected
397.v907382dd9b_98 - < *
unaffected
378.380.v545b_1154b_3fb_ - < 378.*

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now