Jenkins Azure AD Plugin 396.v86ce29279947 and earlier, except 378.380.v545b1154b3fb_, uses a non-constant time comparison function when checking whether the provided and expected CSRF protection nonce are equal, potentially allowing attackers to use statistical methods to obtain a valid nonce.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "348.vefd011eea_20b"
},
{
"introduced": "378.vd6e2874a_69eb"
},
{
"last_affected": "396.v86ce29279947"
}
]
}