PT-2022-14238 · Gogs · Gogs

Published

2022-06-08

·

Updated

2024-08-21

·

CVE-2022-1986

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions gogs/gogs versions prior to 0.12.9
Description The issue allows a malicious user to update a crafted config file into the repository's .git directory, combined with crafted file deletion, to gain SSH access to the server. This affects all installations with repository upload enabled, which is the default setting.
Recommendations For versions prior to 0.12.9, upgrade to 0.12.9 or the latest 0.13.0+dev to resolve the issue. As a temporary workaround, consider restricting access to the .git directory to minimize the risk of exploitation.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-1986
GHSA-67MX-JC2F-JGJM
GO-2022-0556

Affected Products

Gogs