Critical RCE Bug in Gogs Git Service Remains Unpatched
TL;DR. A high-severity remote code execution vulnerability in the open-source Git service Gogs has no patch, with an exploit module now public. - The bug allows authenticated users to compromise servers, steal credentials, and modify code in repositories. - Rapid7 researcher Jonah Burgess reported the flaw in March, but Gogs maintainers have not responded. - A public Metasploit module is available, suggesting imminent exploitation in the wild.
- A critical remote code execution (RCE) vulnerability exists in Gogs, a popular open-source Git service.
- The flaw allows any authenticated user to fully compromise vulnerable servers, access credentials, and alter code.
- Researcher Jonah Burgess reported the bug in March; Gogs maintainers have not issued a patch or responded to updates.
- A public Metasploit exploit module now exists, increasing the likelihood of in-the-wild attacks.
- The vulnerability affects Windows, Linux, and macOS installations of Gogs.