Vulnerability index

Browse CVEs

47 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Gogs HIGH 8.1
CVE-2022-1993EPSS 52%

Path Traversal in GitHub repository gogs/gogs prior to 0.12.9.

Fix: 0.12.9+
Fix from $1,950 2022-06-09
Gogs HIGH 8.8
CVE-2021-32546

Missing input validation in internal/db/repo_editor.go in Gogs before 0.12.8 allows an attacker to execute code remotely. An unprivileged attacker (r…

Fix: 0.12.8+
Fix from $1,950 2022-06-02
Gogs MEDIUM 6.5
CVE-2022-1285

Server-Side Request Forgery (SSRF) in GitHub repository gogs/gogs prior to 0.12.8.

Fix: 0.12.8+
Fix from $1,600 2022-06-01
Gogs MEDIUM 5.4
CVE-2022-1464

Stored xss bug in GitHub repository gogs/gogs prior to 0.12.7. As the repo is public , any user can view the report and when open the attachment then…

Fix: 0.12.7+
Fix from $1,600 2022-05-05
Gogs HIGH 8.8
CVE-2022-0415EPSS 65%

Remote Command Execution in uploading repository file in GitHub repository gogs/gogs prior to 0.12.6.

Fix: 0.12.6+
Fix from $1,950 2022-03-21
Gogs CRITICAL 9.1
CVE-2022-0871

Missing Authorization in GitHub repository gogs/gogs prior to 0.12.5.

Fix: 0.12.5+
Fix from $2,300 2022-03-11
Gogs MEDIUM 5.3
CVE-2022-0870

Server-Side Request Forgery (SSRF) in GitHub repository gogs/gogs prior to 0.12.5.

Fix: 0.12.5+
Fix from $1,600 2022-03-11
Gogs HIGH 7.2
CVE-2020-15867EPSS 87%

The git hook feature in Gogs 0.5.5 through 0.12.2 allows for authenticated remote code execution. There can be a privilege escalation if access to th…

Fix: after 0.12.2
Fix from $1,950 2020-10-16
Gogs MEDIUM 6.5
CVE-2020-14958

In Gogs 0.11.91, MakeEmailPrimary in models/user_mail.go lacks a "not the owner of the email" check.

Patch available
Fix from $1,600 2020-06-21
Gogs MEDIUM 5.9
CVE-2020-9329

Gogs through 0.11.91 allows attackers to violate the admin-specified repo-creation policy due to an internal/db/repo.go race condition.

Fix: after 0.11.91
Fix from $1,600 2020-02-21
Gogs CRITICAL 9.8
CVE-2019-14544

routes/api/v1/api.go in Gogs 0.11.86 lacks permission checks for routes: deploy keys, collaborators, and hooks.

Patch available
Fix from $2,300 2019-08-02
Gogs HIGH 7.5
CVE-2018-20303

In pkg/tool/path.go in Gogs before 0.11.82.1218, a directory traversal in the file-upload functionality can allow an attacker to create a file under …

Fix: 0.11.82.1218+
Fix from $1,950 2018-12-20
Gogs CRITICAL 9.8
CVE-2018-18925EPSS 31%

Gogs 0.11.66 allows remote code execution because it does not properly validate session IDs, as demonstrated by a ".." session-file forgery in the fi…

Fix: after 0.11.66
Fix from $2,300 2018-11-04
Gogs MEDIUM 6.1
CVE-2018-17031

In Gogs 0.11.53, an attacker can use a crafted .eml file to trigger MIME type sniffing, which leads to XSS, as demonstrated by Internet Explorer, bec…

No fix yet
Fix from $1,600 2018-09-14
Gogs HIGH 8.6
CVE-2018-16409

In Gogs 0.11.53, an attacker can use migrate to send arbitrary HTTP GET requests, leading to SSRF.

Mitigation only
Fix from $1,950 2018-09-03
Gogs HIGH 8.8
CVE-2018-15193

A CSRF vulnerability in the admin panel in Gogs through 0.11.53 allows remote attackers to execute admin operations via a crafted issue / link.

No fix yet
Fix from $1,950 2018-08-08
Gogs MEDIUM 6.1
CVE-2018-15178

Open redirect vulnerability in Gogs before 0.12 allows remote attackers to redirect users to arbitrary websites and conduct phishing attacks via an i…

Fix: 0.12+
Fix from $1,600 2018-08-08