Loading HuntDB...

GHSA-fpj7-9xm6-8hgr

GitHub Security Advisory

Observable Discrepancy and Observable Timing Discrepancy in Jenkins Configuration as Code Plugin

✓ GitHub Reviewed LOW Has CVE

Advisory Details

Jenkins Configuration as Code Plugin prior to 1.55.1, 1.54.1, 1.53.1, and 1.47.1 does not use a constant-time comparison when checking whether two authentication tokens are equal.

This could potentially allow attackers to use statistical methods to obtain a valid authentication token.

Configuration as Code Plugin 1.55.1, 1.54.1, 1.53.1, and 1.47.1 now uses a constant-time comparison when validating authentication tokens.

Affected Packages

Maven io.jenkins:configuration-as-code
Affected versions: 1.55 (fixed in 1.55.1)
Maven io.jenkins:configuration-as-code
Affected versions: 1.54 (fixed in 1.54.1)
Maven io.jenkins:configuration-as-code
Affected versions: 1.48 (fixed in 1.53.1)
Maven io.jenkins:configuration-as-code
Affected versions: 0 (fixed in 1.47.1)

Related CVEs

Key Information

GHSA ID
GHSA-fpj7-9xm6-8hgr
Published
January 21, 2022 11:38 PM
Last Modified
May 24, 2023 2:00 PM
CVSS Score
2.5 /10
Primary Ecosystem
Maven
Primary Package
io.jenkins:configuration-as-code
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 4, 2025 6:27 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.