The webhook endpoint in Jenkins Gogs Plugin 1.0.15 and earlier provides unauthenticated attackers information about the existence of jobs in its output.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Gogs |
Jenkins |
* |
1.0.15 (including) |
References