CVE-2024-23903 affects Jenkins GitLab Branch Source Plugin versions 684.vea_fa_7c1e2fe3 and earlier. This medium-severity vulnerability (CVSS 5.3) stems from a non-constant time comparison function for webhook tokens, allowing attackers to potentially deduce valid tokens through statistical analysis. The attack requires no user interaction and has low complexity, leading to a potential compromise of confidentiality. There is no evidence of active exploitation, public exploit code, or inclusion in CISA's KEV catalog, though it has garnered some community discussion and limited media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 684.vea_fa_7c1e2fe3CPE matchmatch criteria | cpe:2.3:a:jenkins:github_branch_source:*:*:*:*:*:jenkins:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.