CVE-2022-34174
Java vulnerability analysis and mitigation

Overview

CVE-2022-34174 is a security vulnerability discovered in Jenkins 2.355 and earlier, LTS 2.332.3 and earlier, disclosed on June 22, 2022. The vulnerability allows attackers to determine the validity of usernames through an observable timing discrepancy on the login form when using the Jenkins user database security realm (Jenkins Advisory).

Technical details

The vulnerability manifests as a timing discrepancy in the login form that allows distinguishing between login attempts with an invalid username and login attempts with a valid username and wrong password. This vulnerability is rated as Medium severity according to CVSS scoring system. The issue was tracked as SECURITY-2566 internally by the Jenkins security team (Jenkins Advisory).

Impact

The vulnerability enables attackers to determine whether specific usernames exist in the system by observing timing differences in login attempt responses. This information disclosure could be used as a stepping stone for further attacks by helping attackers identify valid user accounts (Jenkins Advisory).

Mitigation and workarounds

The vulnerability was fixed in Jenkins 2.356 and LTS 2.332.4. The fix involves validating a synthetic password for login attempts with invalid usernames to eliminate the timing discrepancy. Users are advised to upgrade to these versions or later to address the vulnerability (Jenkins Advisory).

Community reactions

The vulnerability was discovered and reported by Anders Lundman of WithSecure, demonstrating the active involvement of security researchers in identifying Jenkins security issues (Jenkins Advisory).

Additional resources


SourceThis report was generated using AI

Related Java vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-55749HIGH8.7
  • JavaJava
  • org.xwiki.platform:xwiki-platform-tool-jetty-resources
NoYesDec 01, 2025
CVE-2025-13806MEDIUM6.9
  • JavaJava
  • org.nutz:nutzboot-parent
NoNoDec 01, 2025
CVE-2025-13805MEDIUM6.3
  • JavaJava
  • org.nutz:nutzboot-parent
NoNoDec 01, 2025
CVE-2025-13804MEDIUM5.3
  • JavaJava
  • org.nutz:nutzboot-parent
NoNoDec 01, 2025
CVE-2025-66372LOW2.8
  • JavaJava
  • org.mustangproject:library
NoYesNov 28, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management