First published: Wed Jun 22 2022(Updated: )
In Jenkins 2.355 and earlier, LTS 2.332.3 and earlier, an observable timing discrepancy on the login form allows distinguishing between login attempts with an invalid username, and login attempts with a valid username and wrong password, when using the Jenkins user database security realm.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/jenkins | <0:2.361.1.1675406172-1.el8 | 0:2.361.1.1675406172-1.el8 |
redhat/jenkins | <0:2.361.1.1672840472-1.el8 | 0:2.361.1.1672840472-1.el8 |
redhat/jenkins | <0:2.361.1.1675668150-1.el8 | 0:2.361.1.1675668150-1.el8 |
<=2.332.3 | ||
<=2.355 | ||
Jenkins Jenkins | <=2.332.3 | |
Jenkins Jenkins | <=2.355 | |
maven/org.jenkins-ci.main:jenkins-core | <2.332.4 | 2.332.4 |
maven/org.jenkins-ci.main:jenkins-core | >=2.334<2.356 | 2.356 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2022-34174 is a vulnerability in Jenkins that allows an observable timing discrepancy on the login form, allowing an attacker to distinguish between login attempts with an invalid username and login attempts with a valid username and wrong password.
CVE-2022-34174 has a severity rating of 7.5 (High).
CVE-2022-34174 impacts Jenkins versions 2.355 and earlier LTS 2.332.3 and earlier by allowing an attacker to distinguish between login attempts with different types of credentials.
The remedy for CVE-2022-34174 is to update Jenkins to version 2.356 or later, or LTS to version 2.332.4 or later.
More information about CVE-2022-34174 can be found at the following references: [CVE Details](https://www.cve.org/CVERecord?id=CVE-2022-34174), [NVD](https://nvd.nist.gov/vuln/detail/CVE-2022-34174), [Jenkins Security Advisory](https://www.jenkins.io/security/advisory/2022-06-22/#SECURITY-2566), [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=2119653), [Red Hat Errata](https://access.redhat.com/errata/RHSA-2023:0697).