Lucene search

K
prionPRIOn knowledge basePRION:CVE-2022-43412
HistoryOct 19, 2022 - 4:15 p.m.

Design/Logic Flaw

2022-10-1916:15:00
PRIOn knowledge base
www.prio-n.com
4
jenkins
plugin
webhook
comparison
vulnerability

0.001 Low

EPSS

Percentile

33.5%

Jenkins Generic Webhook Trigger Plugin 1.84.1 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token are equal, potentially allowing attackers to use statistical methods to obtain a valid webhook token.

CPENameOperatorVersion
generic_webhook_triggerlt1.84.2

0.001 Low

EPSS

Percentile

33.5%

Related for PRION:CVE-2022-43412