CVE-2023-40349

CWE-6655 documents5 sources
Severity
5.3MEDIUM
EPSS
0.2%
top 63.57%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 16

Description

Jenkins Gogs Plugin 1.0.15 and earlier improperly initializes an option to secure its webhook endpoint, allowing unauthenticated attackers to trigger builds of jobs.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages3 packages

🔴Vulnerability Details

3
GHSA
Jenkins Gogs Plugin vulnerable to unsafe default behavior and information disclosure2023-08-16
CVEList
CVE-2023-40349: Jenkins Gogs Plugin 12023-08-16
OSV
Jenkins Gogs Plugin vulnerable to unsafe default behavior and information disclosure2023-08-16

📋Vendor Advisories

1
Jenkins
Jenkins Security Advisory 2023-08-162023-08-16
CVE-2023-40349 (MEDIUM CVSS 5.3) | Jenkins Gogs Plugin 1.0.15 and earl | cvebase.io