-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.jenkins-ci.plugins:gogs-webhook | maven | <= 1.0.14 | 1.0.15 |
The vulnerable functions are identified based on the changes made to handle the gogsSecret securely. The original handling of gogsSecret as a plain String in GogsProjectProperty was insecure, and the patch updated this to use Jenkins' Secret class for secure handling.
Ongoing coverage of React2Shell