GHSA-rc33-44qp-vpvq

    Dashboard / Vulnerabilities / GHSA-rc33-44qp-vpvq

    GHSA-rc33-44qp-vpvq

    Published: 16 Aug 2023Last Modified: 16 Feb 2024

    Summary: Jenkins Gogs Plugin vulnerable to unsafe default behavior and information disclosure

    Details: Jenkins Gogs Plugin provides a webhook endpoint at /gogs-webhook that can be used to trigger builds of jobs. In Gogs Plugin 1.0.15 and earlier, an option to specify a Gogs secret for this webhook is provided, but not enabled by default. This allows unauthenticated attackers to trigger builds of jobs corresponding to the attacker-specified job name. Additionally, the output of the webhook endpoint includes whether a job corresponding to the attacker-specified job name exists, even if the attacker has no permission to access it. As of publication of this advisory, there is no fix.

    Affected packages

    Package

    Name: org.jenkins-ci.plugins:gogs-webhook

    Purl: pkg:maven/org.jenkins-ci.plugins/gogs-webhook

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -None

    Affected versions

    1.0.0
    1.0.10
    1.0.11
    1.0.12
    1.0.13
    1.0.14
    1.0.15
    1.0.2
    1.0.3
    1.0.4
    1.0.6
    1.0.7
    1.0.8
    1.0.9

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-rc33-44qp-vpvq | CVE-DB