CVE-2022-1285: Server-Side Request Forgery in gogs webhook
Server-Side Request Forgery (SSRF) in GitHub repository gogs/gogs prior to 0.12.8.
References
- github.com/advisories/GHSA-w689-557m-2cvq
- github.com/gogs/gogs/commit/7885f454a4946c4bbec1b4f8c603b5eea7429c7f
- github.com/gogs/gogs/security/advisories/GHSA-w689-557m-2cvq
- huntr.dev/bounties/da1fbd6e-7a02-458e-9c2e-6d226c47046d
- huntr.dev/bounties/da1fbd6e-7a02-458e-9c2e-6d226c47046d/
- nvd.nist.gov/vuln/detail/CVE-2022-1285
Detect and mitigate CVE-2022-1285 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →