Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:39567
HistoryMar 07, 2023 - 12:49 a.m.

Information Disclosure

2023-03-0700:49:21
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6
jenkins-2-plugins
information disclosure
vulnerability
non-constant time comparison
webhook signatures
statistical methods

0.001 Low

EPSS

Percentile

33.5%

jenkins-2-plugins is vulnerable to Information Disclosure. The vulnerability exists due to the non-constant time comparison function in the library when checking whether the provided and computed webhook signatures are equal, allowing attackers to use statistical methods to obtain a valid webhook signature.

0.001 Low

EPSS

Percentile

33.5%