Show filters
34 Total Results
Displaying 21-30 of 34
Sort by:
Attacker Value
Unknown
CVE-2020-14958
Disclosure Date: June 21, 2020 (last updated February 21, 2025)
In Gogs 0.11.91, MakeEmailPrimary in models/user_mail.go lacks a "not the owner of the email" check.
0
Attacker Value
Unknown
CVE-2020-9329
Disclosure Date: February 21, 2020 (last updated February 21, 2025)
Gogs through 0.11.91 allows attackers to violate the admin-specified repo-creation policy due to an internal/db/repo.go race condition.
0
Attacker Value
Unknown
CVE-2019-14544
Disclosure Date: August 02, 2019 (last updated November 27, 2024)
routes/api/v1/api.go in Gogs 0.11.86 lacks permission checks for routes: deploy keys, collaborators, and hooks.
0
Attacker Value
Unknown
CVE-2019-10348
Disclosure Date: July 11, 2019 (last updated October 26, 2023)
Jenkins Gogs Plugin stored credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
0
Attacker Value
Unknown
CVE-2018-20303
Disclosure Date: December 20, 2018 (last updated November 27, 2024)
In pkg/tool/path.go in Gogs before 0.11.82.1218, a directory traversal in the file-upload functionality can allow an attacker to create a file under data/sessions on the server, a similar issue to CVE-2018-18925.
0
Attacker Value
Unknown
CVE-2018-18925
Disclosure Date: November 04, 2018 (last updated November 27, 2024)
Gogs 0.11.66 allows remote code execution because it does not properly validate session IDs, as demonstrated by a ".." session-file forgery in the file session provider in file.go. This is related to session ID handling in the go-macaron/session code for Macaron.
0
Attacker Value
Unknown
CVE-2018-17031
Disclosure Date: September 14, 2018 (last updated November 27, 2024)
In Gogs 0.11.53, an attacker can use a crafted .eml file to trigger MIME type sniffing, which leads to XSS, as demonstrated by Internet Explorer, because an "X-Content-Type-Options: nosniff" header is not sent.
0
Attacker Value
Unknown
CVE-2018-16409
Disclosure Date: September 03, 2018 (last updated November 27, 2024)
In Gogs 0.11.53, an attacker can use migrate to send arbitrary HTTP GET requests, leading to SSRF.
0
Attacker Value
Unknown
CVE-2018-15193
Disclosure Date: August 08, 2018 (last updated November 27, 2024)
A CSRF vulnerability in the admin panel in Gogs through 0.11.53 allows remote attackers to execute admin operations via a crafted issue / link.
0
Attacker Value
Unknown
CVE-2018-15192
Disclosure Date: August 08, 2018 (last updated November 27, 2024)
An SSRF vulnerability in webhooks in Gitea through 1.5.0-rc2 and Gogs through 0.11.53 allows remote attackers to access intranet services.
0