Description
Jenkins before 1.650 and LTS before 1.642.2 do not use a constant-time algorithm to verify CSRF tokens, which makes it easier for remote attackers to bypass a CSRF protection mechanism via a brute-force approach.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP Photo Album Plus 'wppa-album' Parameter SQL Injection (4.1.1)
Joomla! Core 3.x.x Security Bypass (3.8.8 - 3.9.16)
MySQL CVE-2014-6464 Vulnerability (CVE-2014-6464)
WordPress Plugin Custom Website Data Cross-Site Scripting (2.2)
WordPress Plugin Product Catalog Multiple Vulnerabilities (3.1.2)