Gogs
Jenkins · 4 CVEs
CVE-2023-46657
MEDIUM
Jenkins Gogs Plugin 1.0.15 and earlier uses a non-constant time comparison function when checking whether the provided…
Oct 25, 2023
CVE-2023-40349
MEDIUM
Jenkins Gogs Plugin 1.0.15 and earlier improperly initializes an option to secure its webhook endpoint, allowing unauth…
Aug 16, 2023
CVE-2023-40348
MEDIUM
The webhook endpoint in Jenkins Gogs Plugin 1.0.15 and earlier provides unauthenticated attackers information about the…
Aug 16, 2023
CVE-2019-10348
HIGH
Jenkins Gogs Plugin stored credentials unencrypted in job config.xml files on the Jenkins master where they can be view…
Jul 11, 2019
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2023-46657 | Jenkins Gogs Plugin 1.0.15 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token are equal, po… | MEDIUM | 0.57% | Oct 25, 2023 |
| CVE-2023-40349 | Jenkins Gogs Plugin 1.0.15 and earlier improperly initializes an option to secure its webhook endpoint, allowing unauthenticated attackers to trigger builds of… | MEDIUM | 0.68% | Aug 16, 2023 |
| CVE-2023-40348 | The webhook endpoint in Jenkins Gogs Plugin 1.0.15 and earlier provides unauthenticated attackers information about the existence of jobs in its output. | MEDIUM | 0.65% | Aug 16, 2023 |
| CVE-2019-10348 | Jenkins Gogs Plugin stored credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permissio… | HIGH | 1.67% | Jul 11, 2019 |
Showing 1 to 4 of 4 CVEs