CRITICAL
Remote Command Execution in gogs/gogs
Published Nov 15, 2024
10.0
CRITICALCVSS 3.1
EPSS 1.84%
Description
A remote command execution vulnerability exists in gogs/gogs versions <=0.12.7 when deployed on a Windows server. The vulnerability arises due to improper validation of the `tree_path` parameter during file uploads. An attacker can set `tree_path=.git.` to upload a file into the .git directory, allowing them to write or rewrite the `.git/config` file. If the `core.sshCommand` is set, this can lead to remote command execution.
Affected products
-
Affected
- ≥ unspecified, ≤ latest
-
Affected
- ≥ 0, ≤ 0.12.7
No Red Hat product state for this CVE.
gogs.io/gogs
Go
Introduced 0 Fixed 0.12.8
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | gogs.io/gogs | 0 | 0.12.8 |
Remediation
No remediation recorded yet.
Weaknesses (2)
References (10)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-6003 Advisory
- https://github.com/advisories/GHSA-958j-443g-7mm7 Advisory
- https://github.com/gogs/gogs/blob/f36eeedbf89328ee70cc3a2e239f6314f9021f58/conf/app.ini#L127-L129
- https://github.com/gogs/gogs/issues/6968
- https://github.com/gogs/gogs/pull/6970
- https://github.com/gogs/gogs/releases/tag/v0.12.8
- https://github.com/gogs/gogs/security/advisories/GHSA-958j-443g-7mm7
- https://huntr.com/bounties/9cd4e7b7-0979-4e5e-9a1c-388b58dea76b ExploitThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-1884
- https://www.huntr.dev/bounties/9cd4e7b7-0979-4e5e-9a1c-388b58dea76b
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner @huntr_ai
Published Nov 15, 2024
Updated Nov 15, 2024
Reserved May 25, 2022
Link CVE-2022-1884
CISA Vulnrichment
Updated Nov 15, 2024
Red Hat
No data
GitHub
Link GHSA-958J-443G-7MM7