Remote Command Execution in uploading repository file in GitHub repository gogs/gogs prior to 0.12.6.
References
Link | Resource |
---|---|
https://github.com/gogs/gogs/commit/0fef3c9082269e9a4e817274942a5d7c50617284 | Patch Third Party Advisory |
https://huntr.dev/bounties/b4928cfe-4110-462f-a180-6d5673797902 | Exploit Patch Third Party Advisory |
Configurations
Information
Published : 2022-03-21 04:15
Updated : 2022-03-25 11:14
NVD link : CVE-2022-0415
Mitre link : CVE-2022-0415
JSON object : View
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type
Products Affected
gogs
- gogs