Description
Jenkins 2.218 and earlier, LTS 2.204.1 and earlier did not use a constant-time comparison function for validating connection secrets, which could potentially allow an attacker to use a timing attack to obtain this secret.
Remediation
References
Related Vulnerabilities
WordPress Plugin Showbiz Pro Responsive Teaser Arbitrary File Upload (1.7.1)
Oracle JRE Incorrect Conversion between Numeric Types Vulnerability (CVE-2022-34169)
OpenSSL Inefficient Regular Expression Complexity Vulnerability (CVE-2023-3446)
WordPress Plugin All-In-One Security (AIOS)-Security and Firewall Directory Traversal (5.1.4)