CVE-2022-36885

Source
https://nvd.nist.gov/vuln/detail/CVE-2022-36885
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-36885.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-36885
Aliases
Related
Withdrawn
2024-05-08T06:52:28.966807Z
Published
2022-07-27T15:15:08Z
Modified
2023-11-28T23:14:49.484540Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
[none]
Details

Jenkins GitHub Plugin 1.34.4 and earlier uses a non-constant time comparison function when checking whether the provided and computed webhook signatures are equal, allowing attackers to use statistical methods to obtain a valid webhook signature.

References

Affected packages

Git / github.com/jenkinsci/github-plugin

Affected ranges

Type
GIT
Repo
https://github.com/jenkinsci/github-plugin
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

github-0.*

github-0.3
github-0.4
github-0.5
github-0.6
github-0.7
github-0.8
github-0.9

github-1.*

github-1.0
github-1.1
github-1.10
github-1.11
github-1.11.1
github-1.11.2
github-1.11.3
github-1.12.0
github-1.12.0-alpha-1
github-1.12.1
github-1.13.0
github-1.13.0-alpha-1
github-1.13.0-alpha-2
github-1.14.0
github-1.14.0-alpha-1
github-1.14.0-alpha-2
github-1.14.1
github-1.14.2
github-1.15.0
github-1.16.0
github-1.17.0
github-1.17.1
github-1.18.0
github-1.18.1
github-1.18.2
github-1.19.0
github-1.2
github-1.3
github-1.4
github-1.5
github-1.6
github-1.7
github-1.8
github-1.9
github-1.9.1

v1.*

v1.19.1
v1.19.2
v1.19.3
v1.20.0
v1.21.0
v1.21.1
v1.22.0
v1.22.1
v1.22.2
v1.22.3
v1.22.4
v1.23.0
v1.23.1
v1.24.0
v1.25.1
v1.26.0
v1.26.1
v1.26.2
v1.27.0
v1.28.0
v1.28.1
v1.29.0
v1.29.1
v1.29.2
v1.29.3
v1.29.4
v1.29.5
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.34.1
v1.34.2
v1.34.3
v1.34.4