Description
Jenkins before 1.650 and LTS before 1.642.2 do not use a constant-time algorithm to verify API tokens, which makes it easier for remote attackers to determine API tokens via a brute-force approach.
Remediation
References
Related Vulnerabilities
WordPress Plugin Groundhogg-Marketing Automation & CRM for WordPress SQL Injection (1.3.11.13)
WordPress Plugin Modern Events Calendar Lite Cross-Site Scripting (5.22.2)
WordPress Plugin FCChat Widget 'path' Parameter Cross-Site Scripting (2.1.7)
Nginx Uncontrolled Resource Consumption Vulnerability (CVE-2018-16844)
Grafana Insufficiently Protected Credentials Vulnerability (CVE-2019-15635)