Lucene search

K
prionPRIOn knowledge basePRION:CVE-2022-36885
HistoryJul 27, 2022 - 3:15 p.m.

Code injection

2022-07-2715:15:00
PRIOn knowledge base
www.prio-n.com
6

5.8 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

33.5%

Jenkins GitHub Plugin 1.34.4 and earlier uses a non-constant time comparison function when checking whether the provided and computed webhook signatures are equal, allowing attackers to use statistical methods to obtain a valid webhook signature.

CPENameOperatorVersion
githuble1.34.4

5.8 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

33.5%