VDB
CVE-2022-34174
CVE-2022-34174
PUBLISHED
CVSS 7.5 HIGH
In Jenkins 2.355 and earlier, LTS 2.332.3 and earlier, an observable timing discrepancy on the login form allows distinguishing between login attempts with an invalid username, and login attempts with a valid username and wrong password, when using the Jenkins user database security realm.
EPSS 1.59% · 74.6th percentile
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
1.59%
74.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | jenkins | 0 |
| Bitnami | jenkins | 0 |
Timeline
- Jun 22, 2022 CVE Published
- Jun 23, 2022 EPSS Score
- Aug 11, 2022 EPSS Score
- Nov 16, 2022 EPSS Score
- Jan 3, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 10, 2023 EPSS Score
- May 28, 2023 EPSS Score
- Sep 2, 2023 EPSS Score
- Oct 20, 2023 EPSS Score
- Jan 25, 2024 EPSS Score
- Mar 13, 2024 EPSS Score