First published: Wed Aug 16 2023(Updated: )
Jenkins Gogs Plugin 1.0.15 and earlier improperly initializes an option to secure its webhook endpoint, allowing unauthenticated attackers to trigger builds of jobs.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Gogs | <=1.0.15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-40349 is a vulnerability in Jenkins Gogs Plugin 1.0.15 and earlier that allows unauthenticated attackers to trigger builds of jobs.
The severity of CVE-2023-40349 is medium with a CVSS score of 6.5.
CVE-2023-40349 affects Jenkins Gogs Plugin 1.0.15 and earlier versions by improperly initializing an option that secures its webhook endpoint.
The CVE-2023-40349 vulnerability can be exploited by unauthenticated attackers to trigger builds of jobs using the Gogs Plugin webhook endpoint.
To fix the CVE-2023-40349 vulnerability, update Jenkins Gogs Plugin to version 1.0.16 or later.