CVE-2023-40349
Description
Jenkins Gogs Plugin 1.0.15 and earlier improperly initializes an option to secure its webhook endpoint, allowing unauthenticated attackers to trigger builds of jobs.
References
Vendor Advisory
Mailing ListThird Party Advisory
CvssV3 impact
Could not find any metrics
CvssV2 impact
Could not find any metrics