Lucene search

K
nvd[email protected]NVD:CVE-2023-46660
HistoryOct 25, 2023 - 6:17 p.m.

CVE-2023-46660

2023-10-2518:17:40
CWE-697
web.nvd.nist.gov
3
jenkins
zanata plugin
vulnerability
non-constant time
comparison
webhook token
statistical methods

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

AI Score

6

Confidence

High

EPSS

0.001

Percentile

20.2%

Jenkins Zanata Plugin 0.6 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token hashes are equal, potentially allowing attackers to use statistical methods to obtain a valid webhook token.

Affected configurations

Nvd
Node
jenkinszanataRange0.6jenkins
VendorProductVersionCPE
jenkinszanata*cpe:2.3:a:jenkins:zanata:*:*:*:*:*:jenkins:*:*

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

AI Score

6

Confidence

High

EPSS

0.001

Percentile

20.2%