CVE-2023-40348: Jenkins Gogs
Medium severity, CVSS 5.3. EPSS: 0.7% chance of exploitation in the next 30 days.
The webhook endpoint in Jenkins Gogs Plugin 1.0.15 and earlier provides unauthenticated attackers information about the existence of jobs in its output.
Affected products
- Jenkins Gogs: up to and including 1.0.15
Published 2023-08-16. Last modified 2026-06-17.