Unpatched Gogs Zero-Day Allows Remote Code Execution
TL;DR. A new zero-day vulnerability in the self-hosted Git service Gogs enables authenticated attackers to achieve remote code execution on internet-facing instances. - The critical flaw, similar to previous argument injection bugs, affects the latest Gogs versions 0.14.2 and 0.15.0+dev. - Attackers can exploit this by creating malicious pull requests, enabling unauthorized access to repositories and credentials. - Gogs maintainers have acknowledged the report but have not yet provided a patch for the vulnerability.
- An unpatched zero-day vulnerability (RCE) found in Gogs self-hosted Git service.
- Authenticated attackers can exploit the flaw without admin privileges on default configurations.
- Successful exploitation allows access to repositories, credentials, and server compromise.
- Gogs maintainers reported to have acknowledged the flaw but have not yet issued a patch.
Sources
- New Gogs zero-day flaw lets hackers get remote code execution — bleepingcomputer.com