CVE-2023-41936: High severity jenkins vulnerability
Published Sep 6, 2023
·Updated
Jenkins Google Login Plugin 1.7 and earlier uses a non-constant time comparison function when checking whether the provided and expected token are equal, potentially allowing attackers to use statistical methods to obtain a valid token.
Affected Software
1 affected component
jenkins Google Login Jenkins<=1.7
Event History
Sep 6, 2023
CVE Published
12:08 PM
Data Sourced
12:08 PM
Description
Frequently Asked Questions
1
What is CVE-2023-41936?
CVE-2023-41936 is a vulnerability in the Jenkins Google Login Plugin that allows attackers to obtain a valid token using statistical methods.
2
What is the severity of CVE-2023-41936?
The severity of CVE-2023-41936 is high with a CVSS score of 7.5.
3
How does CVE-2023-41936 affect Jenkins Google Login Plugin?
CVE-2023-41936 affects Jenkins Google Login Plugin versions 1.7 and earlier.
4
How can attackers exploit CVE-2023-41936?
Attackers can exploit CVE-2023-41936 by using statistical methods to obtain a valid token.
5
Are there any patches or fixes available for CVE-2023-41936?
Yes, the Jenkins security advisory provides details on how to fix CVE-2023-41936.