cbcvebase.
CVE-2023-40349
published 2023-08-16

CVE-2023-40349: Jenkins Gogs Plugin 1.0.15 and earlier improperly initializes an option to secure its webhook endpoint, allowing unauthenticated attackers to trigger builds of…

medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
Jenkins Gogs Plugin 1.0.15 and earlier improperly initializes an option to secure its webhook endpoint, allowing unauthenticated attackers to trigger builds of jobs.

Affected

15 ranges
VendorProductVersion rangeFixed in
jenkinsblue_ocean_plugin
jenkinsconfig_file_provider_plugin
jenkinsdelphix_plugin
jenkinsdocker_swarm_plugin
jenkinsfavorite_view_plugin
jenkinsflaky_test_handler_plugin
jenkinsfolders_plugin
jenkinsfortify_plugin
jenkinsgogs<= 1.0.15
jenkinsgogs_plugin
jenkinsimproper_masking_of_credentials_in_nodejs_plugin
jenkinsnodejs_plugin
jenkinsshortcut_job_plugin
jenkinstuleap_authentication_plugin
jenkins_projectjenkins_gogs_plugin<= 1.0.15