Filtered by vendor Jenkins Project Subscriptions
Filtered by product Jenkins Webhook Secret Credentials Provider Plugin Subscriptions
Total 1 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2026-70437 1 Jenkins Project 1 Jenkins Webhook Secret Credentials Provider Plugin 2026-08-07 3.7 Low
Jenkins Webhook Secret Credentials Provider Plugin 16.v0cfa_f0215cf5 and earlier does not use a constant-time comparison function when checking whether the provided and expected webhook bearer token are equal, potentially allowing attackers to use statistical methods to obtain a valid webhook bearer token.