PT-2022-13166 · Gogs · Gogs

Published

2022-03-21

·

Updated

2024-08-21

·

CVE-2022-0415

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions gogs versions prior to 0.12.6
Description The issue allows a malicious user to upload a crafted config file into a repository's .git directory to gain SSH access to the server. This affects all installations with repository upload enabled, which is the default setting.
Recommendations For versions prior to 0.12.6, upgrade to 0.12.6 or the latest 0.13.0+dev to resolve the issue. As a temporary workaround, consider disabling repository file uploads to minimize the risk of exploitation.

Exploit

Fix

Unrestricted File Upload

RCE

Weakness Enumeration

Related Identifiers

CVE-2022-0415
GHSA-5GJH-5J4F-CPWV
GO-2022-0554

Affected Products

Gogs