Description
Jenkins 2.218 and earlier, LTS 2.204.1 and earlier used a non-constant time comparison function when validating an HMAC.
Remediation
References
Related Vulnerabilities
PostgreSQL Use of a Broken or Risky Cryptographic Algorithm Vulnerability (CVE-2020-25694)
phpMyAdmin Other Vulnerability (CVE-2007-0095)
MySQL CVE-2018-3070 Vulnerability (CVE-2018-3070)
WordPress Plugin MSMC-Redirect After Comment Multiple Vulnerabilities (2.1.2)
Drupal Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-4553)