Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-40348


The webhook endpoint in Jenkins Gogs Plugin 1.0.15 and earlier provides unauthenticated attackers information about the existence of jobs in its output.


Published

2023-08-16T15:15:12.127

Last Modified

2024-11-21T08:19:16.270

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.3 (MEDIUM)

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo
  • Type: Secondary
    CWE-200

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application jenkins gogs ≤ 1.0.15 Yes

References