#VU65851 Information Exposure Through Timing Discrepancy in GitHub - CVE-2022-36885
Published: July 28, 2022
GitHub
Jenkins
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to the affected plugin does not use a constant-time comparison when checking whether the provided and computed webhook signatures are equal. A remote user can use statistical methods to obtain a valid webhook signature.