{"id":"CVE-2023-41935","details":"Jenkins Azure AD Plugin 396.v86ce29279947 and earlier, except 378.380.v545b_1154b_3fb_, uses a non-constant time comparison function when checking whether the provided and expected CSRF protection nonce are equal, potentially allowing attackers to use statistical methods to obtain a valid nonce.","aliases":["GHSA-hj7p-h74j-6gxj"],"modified":"2026-07-09T09:39:23.870072Z","published":"2023-09-06T13:15:10.297Z","references":[{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2023/09/06/9"},{"type":"ADVISORY","url":"https://www.jenkins.io/security/advisory/2023-09-06/#SECURITY-3227"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/jenkinsci/azure-ad-plugin","events":[{"introduced":"0"},{"last_affected":"efd011eea20b4d91c6381ca8f64ec8f72e7e35fb"},{"introduced":"d6e2874a69eb30e9c0b2917f1193c1b3492a46ce"},{"last_affected":"86ce2927994787fccba21bf6896385e5ad1745cf"}],"database_specific":{"cpe":"cpe:2.3:a:jenkins:azure_ad:*:*:*:*:*:jenkins:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"348.vefd011eea_20b"},{"introduced":"378.vd6e2874a_69eb"},{"last_affected":"396.v86ce29279947"}],"source":"CPE_RANGE"}}],"versions":["396.v86ce29279947","378.vd6e2874a_69eb_","393.v03d1cfd50759","392.v4e15d33fe85d","391.v252da_e1dd39c","385.v5d9f88612dd2","348.vefd011eea_20b_","345.vdb_07735a_767d","340.vdef002cf6415","336.vd05b_01358644","313.v14b_f37ff114d","308.v10a_6e24f30b_4","306.va_7083923fd50","303.va_91ef20ee49f","267.v5b_dfb_514d9fd","241.vb_e5cd7c35b_2e","234.vb_ece34ecd5ff","233.v934e074916c7","218.v90f6a_980b_a_61","213.v5b_00db_295f49","195.v8555a0bf0d22","194.v70a6d5203ce4","191.vfc8019068670","189.v2da14dccdb43","188.v2369adb95a31","185.v3b416408dcb1","184.v44f04b65bdd5","183.vf8c6fa4c6567","180.v8b1e80e6f242","179.vf6841393099e","178.v7b93892fbe4c","177.v80b6c1591bf9","175.v5513346d764a","174.vc2d906355813","173.v0a210fffb510","172.vf6a517c3329a","171.v9ef20c94d336","170.v0a6219442a99","168.ve6e7e368dbf6","167.v34c2c5a3a030","165.v36344b7d7ca7","164.v5b48baa961d2","158.v437429002c6b","157.v2d3d5782a602","155.v745ce80af7ea","154.v12e17a5f9ea3","153.v7af57b288088","152.v1609ed460604","150.vb3db9f880321","146.vb688d1511c38","azure-ad-1.2.3","azure-ad-1.2.2","azure-ad-1.2.1","azure-ad-1.2.0","azure-ad-1.1.2","azure-ad-1.1.1","azure-ad-1.1.0","azure-ad-1.0.0","azure-ad-0.3.4","azure-ad-0.3.3","azure-ad-0.3.2","azure-ad-0.3.1","azure-ad-0.3.0","azure-ad-0.2.0","azure-ad-0.1.1-1","azure-ad-0.1.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-41935.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}