github.com
https://github.com/gogs/gogs CVE-2022-0870
MEDIUMNuclei
Server-Side Request Forgery (SSRF) in gogs/gogs
Record summary
CVE-2022-0870 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.
Description
Server-Side Request Forgery (SSRF) in GitHub repository gogs/gogs prior to 0.12.5.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
gogs/gogsBrowse gogs / gogs/gogs | CVE List | Before 0.12.5 | affected |
gogs.io/gogsBrowse Go / gogs.io/gogs | GitHub Advisory | Before 0.12.5 · Fixed in 0.12.5 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMGogs <0.12.5 - Server-Side Request ForgeryCVSS 5.3
Gogs GitHub repository before 0.12.5 is susceptible to server-side request forgery. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.
Impact
Successful exploitation of this vulnerability can result in unauthorized access to sensitive internal resources.
Remediation
Fixed in version 0.12.5.
WeaknessesCWE-918
Authorstheamanrawat, Akincibor
Template tagscvecve2022ssrfgogsauthenticatedhuntrvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CPE: cpe:2.3:a:gogs:gogs:*:*:*:*:*:*:*:*
Shodan: cpe:"cpe:2.3:a:gogs:gogs"
Shodan: http.title:"sign in - gogs"
FOFA: title="sign in - gogs"
Google: intitle:"sign in - gogs"
https://github.com/gogs/gogs/commit/91f2cde5e95f146bfe4765e837e7282df6c7cabb https://huntr.dev/bounties/327797d7-ae41-498f-9bff-cc0bf98cf531 https://nvd.nist.gov/vuln/detail/CVE-2022-0870 https://github.com/cokeBeer/go-cves https://github.com/michaellrowley/michaellrowley
Source: ProjectDiscovery
References
4github.com
https://github.com/gogs/gogs/commit/91f2cde5e95f146bfe4765e837e7282df6c7cabb huntr.devConfirmation
https://huntr.dev/bounties/327797d7-ae41-498f-9bff-cc0bf98cf531 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-0870