GHSA-fpj7-9xm6-8hgr
GitHub Security Advisory
Observable Discrepancy and Observable Timing Discrepancy in Jenkins Configuration as Code Plugin
✓ GitHub Reviewed
LOW
Has CVE
Advisory Details
Jenkins Configuration as Code Plugin prior to 1.55.1, 1.54.1, 1.53.1, and 1.47.1 does not use a constant-time comparison when checking whether two authentication tokens are equal.
This could potentially allow attackers to use statistical methods to obtain a valid authentication token.
Configuration as Code Plugin 1.55.1, 1.54.1, 1.53.1, and 1.47.1 now uses a constant-time comparison when validating authentication tokens.
Affected Packages
Maven
io.jenkins:configuration-as-code
Affected versions:
1.55
(fixed in 1.55.1)
Maven
io.jenkins:configuration-as-code
Affected versions:
1.54
(fixed in 1.54.1)
Maven
io.jenkins:configuration-as-code
Affected versions:
1.48
(fixed in 1.53.1)
Maven
io.jenkins:configuration-as-code
Affected versions:
0
(fixed in 1.47.1)
Related CVEs
Key Information
2.5
/10
Dataset
Last updated: July 4, 2025 6:27 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.