Unpatched Gogs Zero-Day Allows Remote Code Execution

TL;DR. A new zero-day vulnerability in the self-hosted Git service Gogs enables authenticated attackers to achieve remote code execution on internet-facing instances. - The critical flaw, similar to previous argument injection bugs, affects the latest Gogs versions 0.14.2 and 0.15.0+dev. - Attackers can exploit this by creating malicious pull requests, enabling unauthorized access to repositories and credentials. - Gogs maintainers have acknowledged the report but have not yet provided a patch for the vulnerability.

Sources

Back to QLANKR News