Jenkins Project Jenkins Gogs Plugin vulnerabilities

4 known vulnerabilities affecting jenkins_project/jenkins_gogs_plugin.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2023-46657MEDIUMCVSS 5.3≤ 1.0.152023-10-25
CVE-2023-46657 [MEDIUM] CWE-697 CVE-2023-46657: Jenkins Gogs Plugin 1.0.15 and earlier uses a non-constant time comparison function when checking wh Jenkins Gogs Plugin 1.0.15 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token are equal, potentially allowing attackers to use statistical methods to obtain a valid webhook token.
cvelistv5nvd
CVE-2023-40349MEDIUMCVSS 5.3≤ 1.0.152023-08-16
CVE-2023-40349 [MEDIUM] CWE-665 CVE-2023-40349: Jenkins Gogs Plugin 1.0.15 and earlier improperly initializes an option to secure its webhook endpoi Jenkins Gogs Plugin 1.0.15 and earlier improperly initializes an option to secure its webhook endpoint, allowing unauthenticated attackers to trigger builds of jobs.
cvelistv5nvd
CVE-2023-40348MEDIUMCVSS 5.3≤ 1.0.152023-08-16
CVE-2023-40348 [MEDIUM] CWE-200 CVE-2023-40348: The webhook endpoint in Jenkins Gogs Plugin 1.0.15 and earlier provides unauthenticated attackers in The webhook endpoint in Jenkins Gogs Plugin 1.0.15 and earlier provides unauthenticated attackers information about the existence of jobs in its output.
cvelistv5nvd
CVE-2019-10348HIGHCVSS 8.8v1.0.14 and earlier2019-07-11
CVE-2019-10348 [HIGH] CWE-312 CVE-2019-10348: Jenkins Gogs Plugin stored credentials unencrypted in job config.xml files on the Jenkins master whe Jenkins Gogs Plugin stored credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
cvelistv5nvd