In Jenkins 2.355 and earlier, LTS 2.332.3 and earlier, an observable timing discrepancy on the login form allows distinguishing between login attempts with an invalid username, and login attempts with a valid username and wrong password, when using the Jenkins user database security realm.
| Software | From | Fixed in |
|---|---|---|
| jenkins / jenkins | - | 2.332.3.x |
| jenkins / jenkins | - | 2.355.x |
org.jenkins-ci.main / jenkins-core
|
2.334 | 2.356 |
org.jenkins-ci.main / jenkins-core
|
- | 2.332.4 |