Lucene search

K
cveJenkinsCVE-2022-36885
HistoryJul 27, 2022 - 3:15 p.m.

CVE-2022-36885

2022-07-2715:15:08
CWE-203
jenkins
web.nvd.nist.gov
96
5
jenkins
github plugin
cve-2022-36885
timing attack
security vulnerability

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

AI Score

5.3

Confidence

High

EPSS

0.001

Percentile

33.5%

Jenkins GitHub Plugin 1.34.4 and earlier uses a non-constant time comparison function when checking whether the provided and computed webhook signatures are equal, allowing attackers to use statistical methods to obtain a valid webhook signature.

Affected configurations

Nvd
Node
jenkinsgithubRange1.34.4jenkins
VendorProductVersionCPE
jenkinsgithub*cpe:2.3:a:jenkins:github:*:*:*:*:*:jenkins:*:*

CNA Affected

[
  {
    "product": "Jenkins GitHub Plugin",
    "vendor": "Jenkins project",
    "versions": [
      {
        "lessThanOrEqual": "1.34.4",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      },
      {
        "status": "unaffected",
        "version": "1.34.3.1"
      },
      {
        "status": "unaffected",
        "version": "1.34.1.1"
      }
    ]
  }
]

Social References

More

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

AI Score

5.3

Confidence

High

EPSS

0.001

Percentile

33.5%