Remote Command Execution Vulnerability in Gogs
CVE-2022-1884
What is CVE-2022-1884?
A remote command execution vulnerability is present in Gogs versions prior to 0.12.7 when deployed on Windows servers. This issue is caused by insufficient validation of the tree_path parameter during file uploads, which allows an attacker to manipulate the upload destination. By setting the tree_path to .git., an attacker can upload files to the sensitive .git directory. This can lead to unauthorized modifications of the .git/config file. If the core.sshCommand is configured, it opens the door for remote command execution, potentially enabling attackers to execute arbitrary commands on the affected system.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
gogs/gogs <= unspecified
References
EPSS Score
9% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
