CVE-2023-41935: CSRF
Jenkins Azure AD Plugin 396.v86ce29279947 and earlier, except 378.380.v545b1154b3fb, uses a non-constant time comparison function when checking whether the provided and expected CSRF protection nonce are equal, potentially allowing attackers to use statistical methods to obtain a valid nonce.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-41935?
The severity of CVE-2023-41935 is high with a CVSS score of 7.5.
How does Jenkins Azure AD Plugin 396.v86ce29279947 and earlier, except 378.380.v545b_1154b_3fb_, use a non-constant time comparison function?
Jenkins Azure AD Plugin 396.v86ce29279947 and earlier, except 378.380.v545b_1154b_3fb_, uses a non-constant time comparison function when checking whether the provided and expected CSRF protection nonce are equal.
What is the risk of using non-constant time comparison function in Jenkins Azure AD Plugin?
Using a non-constant time comparison function in Jenkins Azure AD Plugin can potentially allow attackers to use statistical methods to obtain a valid CSRF protection nonce.
Which versions of Jenkins Azure AD Plugin are affected by CVE-2023-41935?
Jenkins Azure AD Plugin versions 396.v86ce29279947 and earlier, except 378.380.v545b_1154b_3fb_, are affected by CVE-2023-41935.
How can I fix the vulnerability in Jenkins Azure AD Plugin?
To fix the vulnerability in Jenkins Azure AD Plugin, update to a version that is later than 396.v86ce29279947 or use a version between 378.380.v545b_1154b_3fb_ and 396.v86ce29279947.