Vulnerabilità ed exploit · Exploit zero-day
Qualsiasi nuovo account Gogs può prendere il controllo della forge Un'installazione predefinita di Gogs offre a un attaccante l'intera forge, non un singolo repo. Il controllo standard di “only trusted repo owners can rebase” non considera che la registrazione aperta e la creazione di repo consentono a uno sconosciuto di creare il proprio account, quindi raggiungere l'esecuzione di comandi lato server tramite rebase merging.
6 fonti · 6 giu
Cronologia Fonti 6 giu The Register Security
No fix yet for critical RCE bug in open-source Git service Gogs - exploit module is out
Researcher reported the vuln in March. Maintainers haven't responded to his messages since
originale 29 mag SecurityWeek
Gogs Zero-Day Exposes Servers to Remote Code Execution
The critical-severity issue, assigned a CVSS score of 9.4, is an argument injection flaw that can be exploited by authenticated attackers via pull requests with malicious branch names.
originale 29 mag The Hacker News
Critical Gogs RCE Vulnerability Lets Any Authenticated User Execute Arbitrary Code
Gogs 9.4 CVSS flaw exploits git rebase injection on 1,141 exposed instances, enabling remote code execution.
originale Part of the PlainSec briefing for 2026-05-28
Every edition of this story: Qualsiasi nuovo account Gogs può prendere il controllo della forge
Altro da oggi
Vulnerabilità ed exploit · Exploit zero-day
Qualsiasi nuovo account Gogs può prendere il controllo della forge Un'installazione predefinita di Gogs offre a un attaccante l'intera forge, non un singolo repo. Il controllo standard di “only trusted repo owners can rebase” non considera che la registrazione aperta e la creazione di repo consentono a uno sconosciuto di creare il proprio account, quindi raggiungere l'esecuzione di comandi lato server tramite rebase merging.
6 fonti · 6 giu
Cronologia Fonti 6 giu The Register Security
No fix yet for critical RCE bug in open-source Git service Gogs - exploit module is out
Researcher reported the vuln in March. Maintainers haven't responded to his messages since
originale 29 mag SecurityWeek
Gogs Zero-Day Exposes Servers to Remote Code Execution
The critical-severity issue, assigned a CVSS score of 9.4, is an argument injection flaw that can be exploited by authenticated attackers via pull requests with malicious branch names.
originale 29 mag The Hacker News
Critical Gogs RCE Vulnerability Lets Any Authenticated User Execute Arbitrary Code
Gogs 9.4 CVSS flaw exploits git rebase injection on 1,141 exposed instances, enabling remote code execution.
originale Part of the PlainSec briefing for 2026-05-28
Every edition of this story: Qualsiasi nuovo account Gogs può prendere il controllo della forge
Altro da oggi