Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q347-cg56-pcq4

Опубликовано: 14 мар. 2022
Источник: github
Github: Прошло ревью
CVSS3: 5

Описание

SSRF in repository migration

Impact

The malicious user is able to discover services in the internal network through repository migration functionality. All installations accepting public traffic are affected.

Patches

Internal network CIDRs are prohibited to be used as repository migration targets. Users should upgrade to 0.12.5 or the latest 0.13.0+dev.

Workarounds

Run Gogs in its own private network.

References

https://www.huntr.dev/bounties/327797d7-ae41-498f-9bff-cc0bf98cf531/

For more information

If you have any questions or comments about this advisory, please post on #6754.

Пакеты

Наименование

gogs.io/gogs

go
Затронутые версииВерсия исправления

< 0.12.5

0.12.5

5 Medium

CVSS3

Дефекты

CWE-918

5 Medium

CVSS3

Дефекты

CWE-918