Critical RCE Vulnerability Found in Gogs Git Service
TL;DR. A critical remote code execution vulnerability affects current Gogs versions, allowing authenticated users to execute arbitrary code on the hosting server. - The flaw enables privilege escalation and server compromise for anyone with valid Gogs credentials. - The vulnerability is present in versions up to 0.12.11 and is fixed in pre-release 0.12.12. - Attackers could exploit this to access sensitive AI models, datasets, or infrastructure hosted via Gogs.
- A remote code execution (RCE) flaw (CVE-2022-21226) exists in Gogs, a self-hosted Git service.
- This vulnerability allows any authenticated user to execute arbitrary commands on the server.
- The RCE could lead to full system compromise and unauthorized access to hosted data and resources.
- Gogs versions up to 0.12.11 are affected; the issue is resolved in pre-release 0.12.12.