Jenkins Tuleap Authentication Plugin non-constant time token comparison
Low severity
GitHub Reviewed
Published
Aug 16, 2023
to the GitHub Advisory Database
•
Updated Nov 11, 2023
Description
Published by the National Vulnerability Database
Aug 16, 2023
Published to the GitHub Advisory Database
Aug 16, 2023
Reviewed
Aug 16, 2023
Last updated
Nov 11, 2023
Jenkins Tuleap Authentication Plugin 1.1.20 and earlier does not use a constant-time comparison when checking whether two authentication tokens are equal.
This could potentially allow attackers to use statistical methods to obtain a valid authentication token.
Tuleap Authentication Plugin 1.1.21 uses a constant-time comparison when validating authentication tokens.
References