Arbitrary Code Execution Affecting gogs.io/gogs package, versions >=0.5.5


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
87.15% (100th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GOGSIOGOGS-7897507
  • published5 Sept 2024
  • disclosed16 Oct 2020
  • creditNiklas Goerke

Introduced: 16 Oct 2020

CVE-2020-15867  (opens in a new tab)
CWE-94  (opens in a new tab)

How to fix?

There is no fixed version for gogs.io/gogs.

Overview

Affected versions of this package are vulnerable to Arbitrary Code Execution. The git hook feature allows for authenticated remote code execution.

CVSS Base Scores

version 3.1