Record summary

CVE-2022-0870 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.

Description

Server-Side Request Forgery (SSRF) in GitHub repository gogs/gogs prior to 0.12.5.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE ListBefore 0.12.5affected
GitHub AdvisoryBefore 0.12.5 · Fixed in 0.12.5affected

Nuclei templates

1
ProjectDiscoveryMEDIUMGogs <0.12.5 - Server-Side Request ForgeryCVSS 5.3

Gogs GitHub repository before 0.12.5 is susceptible to server-side request forgery. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.

Impact

Successful exploitation of this vulnerability can result in unauthorized access to sensitive internal resources.

Remediation

Fixed in version 0.12.5.

WeaknessesCWE-918
Authorstheamanrawat, Akincibor
Template tagscvecve2022ssrfgogsauthenticatedhuntrvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CPE: cpe:2.3:a:gogs:gogs:*:*:*:*:*:*:*:*
Shodan: cpe:"cpe:2.3:a:gogs:gogs"
Shodan: http.title:"sign in - gogs"
FOFA: title="sign in - gogs"
Google: intitle:"sign in - gogs"

Source: ProjectDiscovery

References

4