Description
Jenkins before 1.650 and LTS before 1.642.2 do not use a constant-time algorithm to verify CSRF tokens, which makes it easier for remote attackers to bypass a CSRF protection mechanism via a brute-force approach.
Remediation
References
Related Vulnerabilities
Oracle Database Server CVE-2006-5344 Vulnerability (CVE-2006-5344)
WordPress Plugin 301 Redirects-Easy Redirect Manager Security Bypass (2.40)
WordPress Plugin SendPress Newsletters Cross-Site Scripting (1.20.7.10)
e107 Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-3731)
Perl Integer Overflow or Wraparound Vulnerability (CVE-2020-10878)