Description
Jenkins 2.218 and earlier, LTS 2.204.1 and earlier used a non-constant time comparison function when validating an HMAC.
Remediation
References
Related Vulnerabilities
Joomla! Core 1.0.x Remote File Inclusion (1.0.11 - 1.0.14)
WordPress 3.9.x Denial of Service Vulnerability (3.9 - 3.9.23)
Joomla Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2015-8563)
PHP Missing Release of Resource after Effective Lifetime Vulnerability (CVE-2010-4657)
WordPress Plugin Analytics Stats Counter Statistics PHP Object Injection (1.2.2.5)