Gogs Zero-Day Allows Server Remote Code Execution

TL;DR. A critical zero-day vulnerability in the open source Git service Gogs enables remote code execution on affected servers. - The flaw stems from an argument injection issue exploitable by authenticated attackers using malicious branch names in pull requests. - Rapid7 disclosed the critical vulnerability, assigned a CVSS score of 9.4, affecting the self-hosted Git platform. - Attackers can exploit this without user interaction by leveraging default open registration settings on Gogs instances.

Sources

Back to QLANKR News