Information disclosure in Tuleap Authentication - CVE-2023-40343
Published: August 23, 2023
Tuleap Authentication
Jenkins
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to the affected application does not use a constant-time comparison when checking whether two authentication tokens are equal. A remote attacker can use statistical methods to obtain a valid authentication token.