VDB

CVE-2022-34174

CVE-2022-34174 PUBLISHED

In Jenkins 2.355 and earlier, LTS 2.332.3 and earlier, an observable timing discrepancy on the login form allows distinguishing between login attempts with an invalid username, and login attempts with a valid username and wrong password, when using the Jenkins user database security realm.

EPSS 0.55% · 68.4th percentile

Risk Scores

EPSS Score
0.55%
68.4th percentile

Affected Products

VendorProductVersions
Bitnamijenkins0
Bitnamijenkins0

Timeline

  • Jun 22, 2022 CVE Published
  • Jun 23, 2022 EPSS Score
  • Aug 11, 2022 EPSS Score
  • Nov 14, 2022 EPSS Score
  • Jan 1, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 7, 2023 EPSS Score
  • May 25, 2023 EPSS Score
  • Aug 28, 2023 EPSS Score
  • Oct 15, 2023 EPSS Score
  • Dec 2, 2023 EPSS Score
  • Mar 6, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›