PT-2022-13774 · Gogs · Gogs

Published

2022-06-01

·

Updated

2024-08-21

·

CVE-2022-1285

CVSS v3.1

8.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions gogs/gogs versions prior to 0.12.8
Description The issue is related to a Server-Side Request Forgery (SSRF) in the GitHub repository gogs/gogs. This allows a malicious user to discover services in the internal network through webhook functionality. All installations accepting public traffic are affected.
Recommendations For versions prior to 0.12.8, upgrade to 0.12.8 or the latest 0.13.0+dev to resolve the issue. As a temporary workaround, consider running Gogs in its own private network to minimize the risk of exploitation.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2022-1285
GHSA-W689-557M-2CVQ
GO-2022-0583

Affected Products

Gogs