Vulnerabilities (CVE)

Filtered by vendor Jenkins Subscribe
Filtered by product Gogs
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-40348 1 Jenkins 1 Gogs 2023-08-18 N/A 5.3 MEDIUM
The webhook endpoint in Jenkins Gogs Plugin 1.0.15 and earlier provides unauthenticated attackers information about the existence of jobs in its output.
CVE-2023-40349 1 Jenkins 1 Gogs 2023-08-18 N/A 5.3 MEDIUM
Jenkins Gogs Plugin 1.0.15 and earlier improperly initializes an option to secure its webhook endpoint, allowing unauthenticated attackers to trigger builds of jobs.