webhook-secret-credentials-provider is vulnerable to Observable Timing Discrepancy
37
Low Risk
Webhook bearer token checks do not use a constant-time comparison. An attacker who can make many validation attempts may use timing differences to recover a valid token. The fix compares tokens in constant time.
You are affected if you are using a version that falls within the vulnerable range and validate webhook bearer tokens with this plugin.
webhook-secret-credentials-provider is vulnerable to Observable Timing Discrepancy in versions 0.0.1 - 16.
Upgrade the io.jenkins.plugins:webhook-secret-credentials-provider library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant