Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 07 Aug 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jenkins Project
Jenkins Project jenkins Webhook Secret Credentials Provider Plugin |
|
| Vendors & Products |
Jenkins Project
Jenkins Project jenkins Webhook Secret Credentials Provider Plugin |
Thu, 06 Aug 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Timing Attack Allows Retrieval of Webhook Bearer Token in Jenkins Plugin |
Thu, 06 Aug 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Timing Attack Allowing Secret Bearer Token Disclosure in Jenkins Webhook Secret Credentials Provider Plugin | |
| Weaknesses | CWE-20 CWE-290 |
Thu, 06 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-208 | |
| Metrics |
cvssV3_1
|
Wed, 05 Aug 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Timing Attack Allowing Secret Bearer Token Disclosure in Jenkins Webhook Secret Credentials Provider Plugin | |
| Weaknesses | CWE-20 CWE-290 |
Wed, 05 Aug 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Jenkins Webhook Secret Credentials Provider Plugin 16.v0cfa_f0215cf5 and earlier does not use a constant-time comparison function when checking whether the provided and expected webhook bearer token are equal, potentially allowing attackers to use statistical methods to obtain a valid webhook bearer token. | |
| References |
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2026-08-06T14:55:24.749Z
Reserved: 2026-08-04T14:13:20.602Z
Link: CVE-2026-70437
Updated: 2026-08-06T14:55:06.523Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-07T10:05:34Z