Description
Jenkins 2.218 and earlier, LTS 2.204.1 and earlier did not use a constant-time comparison function for validating connection secrets, which could potentially allow an attacker to use a timing attack to obtain this secret.
Remediation
References
Related Vulnerabilities
PHP4 IMAP module buffer overflow vulnerability
PHP Resource Management Errors Vulnerability (CVE-2014-0237)
WordPress Plugin YITH WooCommerce Waiting List Security Bypass (1.3.9)
Oracle Database Server CVE-2010-3590 Vulnerability (CVE-2010-3590)
MySQL Resource Management Errors Vulnerability (CVE-2010-3678)