Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-6vcc-v9vw-g2x5: Path Traversal in Git HTTP endpoints in Gogs

Impact

The malicious user is able to craft HTTP requests to access unauthorized Git directories. All installations with are affected.

Patches

Path cleaning has accommodated for Git HTTP endpoints. Users should upgrade to 0.12.9 or the latest 0.13.0+dev.

Workarounds

N/A

References

https://huntr.dev/bounties/22f9c074-cf60-4c67-b5c4-72fdf312609d/

For more information

If you have any questions or comments about this advisory, please post on #7002.

ghsa
#vulnerability#git#auth
  1. GitHub Advisory Database
  2. GitHub Reviewed
  3. CVE-2022-1993

Path Traversal in Git HTTP endpoints in Gogs

High severity GitHub Reviewed Published Jun 8, 2022 in gogs/gogs • Updated Jun 8, 2022

Vulnerability details Dependabot alerts 0

Package

gomod gogs.io/gogs (Go )

Affected versions

< 0.12.9

Patched versions

0.12.9

Description

Impact

The malicious user is able to craft HTTP requests to access unauthorized Git directories. All installations with are affected.

Patches

Path cleaning has accommodated for Git HTTP endpoints. Users should upgrade to 0.12.9 or the latest 0.13.0+dev.

Workarounds

N/A

References

https://huntr.dev/bounties/22f9c074-cf60-4c67-b5c4-72fdf312609d/

For more information

If you have any questions or comments about this advisory, please post on #7002.

References

  • GHSA-6vcc-v9vw-g2x5
  • gogs/gogs#7002
  • gogs/gogs@9bf748b
  • https://huntr.dev/bounties/22f9c074-cf60-4c67-b5c4-72fdf312609d/

unknwon published the maintainer security advisory

Jun 8, 2022

Severity

High

Weaknesses

CWE-22

CVE ID

CVE-2022-1993

GHSA ID

GHSA-6vcc-v9vw-g2x5

Source code

gogs/gogs

Credits

  • Sim4n6

See something to contribute? Suggest improvements for this vulnerability.

Related news

CVE-2022-1993: http: clean request path from Git endpoints (#7022) · gogs/gogs@9bf748b

Path Traversal in GitHub repository gogs/gogs prior to 0.12.9.