CVE-2022-0415: Unrestricted Upload of File with Dangerous Type
(updated )
Remote Command Execution in uploading repository file in GitHub repository gogs/gogs prior to 0.12.6.
References
- github.com/advisories/GHSA-5gjh-5j4f-cpwv
- github.com/gogs/gogs/commit/0fef3c9082269e9a4e817274942a5d7c50617284
- github.com/gogs/gogs/issues/6833
- github.com/gogs/gogs/pull/6838
- github.com/gogs/gogs/security/advisories/GHSA-5gjh-5j4f-cpwv
- huntr.dev/bounties/b4928cfe-4110-462f-a180-6d5673797902
- nvd.nist.gov/vuln/detail/CVE-2022-0415
Detect and mitigate CVE-2022-0415 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →