In Jenkins 2.355 and earlier, LTS... CVE-2022-34174

5.0 AV AC AU C I A
发布: 2022-06-23
修订: 2023-11-03

In Jenkins 2.355 and earlier, LTS 2.332.3 and earlier, an observable timing discrepancy on the login form allows distinguishing between login attempts with an invalid username, and login attempts with a valid username and wrong password, when using the Jenkins user database security realm.

0%
暂无可用Exp或PoC
当前有2条受影响产品信息