Jenkins Webhook Secret Credentials Provider Plugin 16.v0cfa_f0215cf5 and earlier does not use a constant-time comparison function when checking whether the provided and expected webhook bearer token are equal, potentially allowing attackers to use statistical methods to obtain a valid webhook bearer token.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 05 Aug 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Timing Attack Allowing Secret Bearer Token Disclosure in Jenkins Webhook Secret Credentials Provider Plugin | |
| Weaknesses | CWE-20 CWE-290 |
Wed, 05 Aug 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Jenkins Webhook Secret Credentials Provider Plugin 16.v0cfa_f0215cf5 and earlier does not use a constant-time comparison function when checking whether the provided and expected webhook bearer token are equal, potentially allowing attackers to use statistical methods to obtain a valid webhook bearer token. | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2026-08-05T17:40:34.627Z
Reserved: 2026-08-04T14:13:20.602Z
Link: CVE-2026-70437
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-05T19:45:03Z