CVE-2023-40349: Jenkins Gogs

Medium severity, CVSS 5.3. EPSS: 0.7% chance of exploitation in the next 30 days.

Jenkins Gogs Plugin 1.0.15 and earlier improperly initializes an option to secure its webhook endpoint, allowing unauthenticated attackers to trigger builds of jobs.

Affected products

  • Jenkins Gogs: up to and including 1.0.15

Published 2023-08-16. Last modified 2026-06-17.