CVE-2023-40348

Severity
5.3MEDIUM
EPSS
0.2%
top 59.01%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 16

Description

The webhook endpoint in Jenkins Gogs Plugin 1.0.15 and earlier provides unauthenticated attackers information about the existence of jobs in its output.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages3 packages

🔴Vulnerability Details

3
OSV
Jenkins Gogs Plugin vulnerable to unsafe default behavior and information disclosure2023-08-16
CVEList
CVE-2023-40348: The webhook endpoint in Jenkins Gogs Plugin 12023-08-16
GHSA
Jenkins Gogs Plugin vulnerable to unsafe default behavior and information disclosure2023-08-16

📋Vendor Advisories

1
Jenkins
Jenkins Security Advisory 2023-08-162023-08-16
CVE-2023-40348 (MEDIUM CVSS 5.3) | The webhook endpoint in Jenkins Gog | cvebase.io