Gogs fixes critical zero-day vulnerability allowing remote code execution

bleepingcomputer.com

Gogs has patched a critical zero-day vulnerability allowing remote code execution and access to private repositories. The flaw, an argument injection vulnerability, affects Gogs releases up to 0.14.2 and 0.15.0+dev. It can be exploited by authenticated users without admin privileges to compromise servers. This vulnerability is similar to past Gogs flaws and highlights the risks of default open registration configurations. Users are urged to upgrade immediately.


With a significance score of 1.9, this news ranks in the top 24% of today's 31359 analyzed articles.

Get summaries of news with significance over 5.5 (usually ~10 stories per week). Read by 10,000+ subscribers:


Gogs fixes critical zero-day vulnerability allowing remote code execution | News Minimalist