cbcvebase.
CVE-2023-40348
published 2023-08-16

CVE-2023-40348: The webhook endpoint in Jenkins Gogs Plugin 1.0.15 and earlier provides unauthenticated attackers information about the existence of jobs in its output.

medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
The webhook endpoint in Jenkins Gogs Plugin 1.0.15 and earlier provides unauthenticated attackers information about the existence of jobs in its output.

Affected

15 ranges
VendorProductVersion rangeFixed in
jenkinsblue_ocean_plugin
jenkinsconfig_file_provider_plugin
jenkinsdelphix_plugin
jenkinsdocker_swarm_plugin
jenkinsfavorite_view_plugin
jenkinsflaky_test_handler_plugin
jenkinsfolders_plugin
jenkinsfortify_plugin
jenkinsgogs<= 1.0.15
jenkinsgogs_plugin
jenkinsimproper_masking_of_credentials_in_nodejs_plugin
jenkinsnodejs_plugin
jenkinsshortcut_job_plugin
jenkinstuleap_authentication_plugin
jenkins_projectjenkins_gogs_plugin<= 1.0.15