Gogs XSS allowed by stored call in PDF renderer
A stored XSS is present in Gogs which allows client-side Javascript code execution.
A stored XSS is present in Gogs which allows client-side Javascript code execution.
Gogs through 0.13.0 allows deletion of internal files.
Gogs through 0.13.0 allows argument injection during the tagging of a new release. This vulnerability is still unfixed as of the time of this advisory being published.
Gogs through 0.13.0 allows argument injection during the previewing of changes.
The built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code execution. Authenticated attackers can exploit this by opening an SSH connection and sending a malicious –split-string env request if the built-in SSH server is activated. Windows installations are unaffected.
This advisory duplicates another.
This advisory duplicates another.
This advisory duplicates another.
This advisory duplicates another.