github.com
https://github.com/gogs/gogs CVE-2022-0415
HIGHNuclei
Remote Command Execution in uploading repository file in gogs/gogs
Record summary
CVE-2022-0415 has a selected CVSS score of 8.8 (high); EIP currently links 1 Nuclei template.
Description
Remote Command Execution in uploading repository file in GitHub repository gogs/gogs prior to 0.12.6.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
gogs/gogsBrowse gogs / gogs/gogs | CVE List | Before 0.12.6 | affected |
gogs.io/gogsBrowse Go / gogs.io/gogs | GitHub Advisory | Before 0.12.6 · Fixed in 0.12.6 | affected |
Nuclei templates
1ProjectDiscoveryHIGHGogs <0.12.6 - Remote Command ExecutionCVSS 8.8
Gogs before 0.12.6 is susceptible to remote command execution via the uploading repository file in GitHub repository gogs/gogs. An attacker can execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials.
Impact
Successful exploitation of this vulnerability allows remote attackers to execute arbitrary commands on the target system.
Remediation
Fixed in version 0.12.6.
WeaknessesCWE-434CWE-20
Authorstheamanrawat
Template tagscvecve2022rcegogsauthenticatedhuntrintrusivevuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:gogs:gogs:*:*:*:*:*:*:*:*
Shodan: cpe:"cpe:2.3:a:gogs:gogs"
Shodan: http.title:"sign in - gogs"
FOFA: title="sign in - gogs"
Google: intitle:"sign in - gogs"
https://github.com/gogs/gogs/commit/0fef3c9082269e9a4e817274942a5d7c50617284 https://huntr.dev/bounties/b4928cfe-4110-462f-a180-6d5673797902 https://nvd.nist.gov/vuln/detail/CVE-2022-0415 https://github.com/bfengj/CTF https://github.com/cokeBeer/go-cves
Source: ProjectDiscovery
References
7github.com
https://github.com/gogs/gogs/commit/0fef3c9082269e9a4e817274942a5d7c50617284 github.com
https://github.com/gogs/gogs/issues/6833 github.com
https://github.com/gogs/gogs/pull/6838 github.com
https://github.com/gogs/gogs/security/advisories/GHSA-5gjh-5j4f-cpwv huntr.devConfirmation
https://huntr.dev/bounties/b4928cfe-4110-462f-a180-6d5673797902 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-0415