VDB

CVE-2022-34174

CVE-2022-34174 PUBLISHED CVSS 7.5 HIGH

In Jenkins 2.355 and earlier, LTS 2.332.3 and earlier, an observable timing discrepancy on the login form allows distinguishing between login attempts with an invalid username, and login attempts with a valid username and wrong password, when using the Jenkins user database security realm.

EPSS 1.59% · 74.6th percentile

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
1.59%
74.6th percentile

Affected Products

VendorProductVersions
Bitnamijenkins0
Bitnamijenkins0

Timeline

  • Jun 22, 2022 CVE Published
  • Jun 23, 2022 EPSS Score
  • Aug 11, 2022 EPSS Score
  • Nov 16, 2022 EPSS Score
  • Jan 3, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 10, 2023 EPSS Score
  • May 28, 2023 EPSS Score
  • Sep 2, 2023 EPSS Score
  • Oct 20, 2023 EPSS Score
  • Jan 25, 2024 EPSS Score
  • Mar 13, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›