CVE-2023-46657: Medium severity jenkins vulnerability
Jenkins Gogs Plugin 1.0.15 and earlier does not use a constant-time comparison when checking whether the provided and expected webhook token are equal.
This could potentially allow attackers to use statistical methods to obtain a valid webhook token.
As of publication of this advisory, there is no fix.
Other sources
Jenkins Gogs Plugin 1.0.15 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token are equal, potentially allowing attackers to use statistical methods to obtain a valid webhook token.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this Jenkins Gogs Plugin vulnerability?
The vulnerability ID of this Jenkins Gogs Plugin vulnerability is CVE-2023-46657.
What is the severity of CVE-2023-46657?
The severity of CVE-2023-46657 is medium with a severity value of 5.3.
What software versions are affected by CVE-2023-46657?
Jenkins Gogs Plugin version 1.0.15 and earlier are affected by CVE-2023-46657.
How can an attacker potentially exploit CVE-2023-46657?
An attacker can potentially exploit CVE-2023-46657 by using statistical methods to obtain a valid webhook token.
Are there any references for CVE-2023-46657?
Yes, the references for CVE-2023-46657 are: http://www.openwall.com/lists/oss-security/2023/10/25/2, https://www.jenkins.io/security/advisory/2023-10-25/#SECURITY-2896, and https://nvd.nist.gov/vuln/detail/CVE-2023-46657.