Critical RCE Vulnerability Found in Gogs Git Service

TL;DR. A critical remote code execution vulnerability affects current Gogs versions, allowing authenticated users to execute arbitrary code on the hosting server. - The flaw enables privilege escalation and server compromise for anyone with valid Gogs credentials. - The vulnerability is present in versions up to 0.12.11 and is fixed in pre-release 0.12.12. - Attackers could exploit this to access sensitive AI models, datasets, or infrastructure hosted via Gogs.

Sources

Back to QLANKR News