Jenkins Gogs Plugin 1.0.15 and earlier improperly initializes an option to secure its webhook endpoint, allowing unauthenticated attackers to trigger builds of jobs.
The product does not initialize or incorrectly initializes a resource, which might leave the resource in an unexpected state when it is accessed or used.
Link | Tags |
---|---|
https://www.jenkins.io/security/advisory/2023-08-16/#SECURITY-2894 | vendor advisory |
http://www.openwall.com/lists/oss-security/2023/08/16/3 | third party advisory mailing list |