ZeroHour

CVE-2023-40349

CVSS 3.1
5.3 medium
EPSS
<1%p50
Published
()
Modified
Description

Jenkins Gogs Plugin 1.0.15 and earlier improperly initializes an option to secure its webhook endpoint, allowing unauthenticated attackers to trigger builds of jobs.

Vendors
jenkins
Products
gogs
Weakness
CWE-665
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.