CVE-2024-39930
- EPSS 7.26%
- Veröffentlicht 04.07.2024 16:15:02
- Zuletzt bearbeitet 11.04.2025 15:14:27
The built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code execution. Authenticated attackers can exploit this by opening an SSH connection and sending a malicious --split-string env reques...
CVE-2022-2024
- EPSS 97.84%
- Veröffentlicht 25.02.2023 08:15:09
- Zuletzt bearbeitet 21.11.2024 07:00:11
OS Command Injection in GitHub repository gogs/gogs prior to 0.12.11.
- EPSS 58.02%
- Veröffentlicht 11.10.2022 15:15:09
- Zuletzt bearbeitet 27.05.2025 21:09:53
In Gogs, versions v0.6.5 through v0.12.10 are vulnerable to Stored Cross-Site Scripting (XSS) that leads to an account takeover.
CVE-2022-31038
- EPSS 0.67%
- Veröffentlicht 09.06.2022 17:15:09
- Zuletzt bearbeitet 21.11.2024 07:03:45
Gogs is an open source self-hosted Git service. In versions of gogs prior to 0.12.9 `DisplayName` does not filter characters input from users, which leads to an XSS vulnerability when directly displayed in the issue list. This issue has been resolved...
CVE-2022-1993
- EPSS 51.14%
- Veröffentlicht 09.06.2022 17:15:08
- Zuletzt bearbeitet 21.11.2024 06:41:54
Path Traversal in GitHub repository gogs/gogs prior to 0.12.9.
CVE-2022-1986
- EPSS 4.48%
- Veröffentlicht 09.06.2022 17:15:08
- Zuletzt bearbeitet 21.11.2024 06:41:53
OS Command Injection in GitHub repository gogs/gogs prior to 0.12.9.
CVE-2022-1992
- EPSS 2.25%
- Veröffentlicht 09.06.2022 17:15:08
- Zuletzt bearbeitet 21.11.2024 06:41:54
Path Traversal in GitHub repository gogs/gogs prior to 0.12.9.
CVE-2021-32546
- EPSS 1.97%
- Veröffentlicht 02.06.2022 14:15:28
- Zuletzt bearbeitet 21.11.2024 06:07:14
Missing input validation in internal/db/repo_editor.go in Gogs before 0.12.8 allows an attacker to execute code remotely. An unprivileged attacker (registered user) can overwrite the Git configuration in his repository. This leads to Remote Command E...
CVE-2022-1285
- EPSS 1.19%
- Veröffentlicht 01.06.2022 06:15:07
- Zuletzt bearbeitet 21.11.2024 06:40:24
Server-Side Request Forgery (SSRF) in GitHub repository gogs/gogs prior to 0.12.8.
CVE-2022-1464
- EPSS 0.67%
- Veröffentlicht 05.05.2022 14:15:08
- Zuletzt bearbeitet 21.11.2024 06:40:46
Stored xss bug in GitHub repository gogs/gogs prior to 0.12.7. As the repo is public , any user can view the report and when open the attachment then xss is executed. This bug allow executed any javascript code in victim account .