Security Advisory

CVE-2022-1884

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2024-11-15 10:53:00
Last updated 2024-11-15 19:15:02
Assigner @huntr_ai
State PUBLISHED

Description

A remote command execution vulnerability exists in gogs/gogs versions <=0.12.7 when deployed on a Windows server. The vulnerability arises due to improper validation of the `tree_path` parameter during file uploads. An attacker can set `tree_path=.git.` to upload a file into the .git directory, allowing them to write or rewrite the `.git/config` file. If the `core.sshCommand` is set, this can lead to remote command execution.