gogs.io/gogs
Gogs is a painless self-hosted Git Service.
Security Advisories for gogs.io/gogs in go
Moderate
about 2 months ago
Gogs's Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS
go
gogs.io/gogs
Moderate
about 2 months ago
Gogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API
go
gogs.io/gogs
Moderate
about 2 months ago
Gogs has Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion)
go
gogs.io/gogs
Critical
about 2 months ago
Gogs has Path Traversal in organization name that results in RCE through Git hooks
go
gogs.io/gogs
High
about 2 months ago
Gogs: LFS dedupe path leaks private repo content across tenants
go
gogs.io/gogs
Critical
about 2 months ago
Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym
go
gogs.io/gogs
High
about 2 months ago
Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion
go
gogs.io/gogs
Moderate
about 2 months ago
Gogs's password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES
go
gogs.io/gogs
High
about 2 months ago
Gogs's write-level collaborators can mutate admin-only repository settings via API
go
gogs.io/gogs
Moderate
about 2 months ago
Gogs has DOM-based XSS via Milestone Name on New Issue Page
go
gogs.io/gogs
Critical
about 2 months ago
Gogs vulnerable to RCE via git rebase --exec argument injection in pull request merge
go
gogs.io/gogs
High
about 2 months ago
Gogs has a Migration Redirect Bypass that Leads to Internal Repository Theft
go
gogs.io/gogs
Moderate
about 2 months ago
Gogs Vulnerable to Privilege Escalation via Collaboration Access Mode Validation
go
gogs.io/gogs
High
about 2 months ago
Gogs has the ability to import local repositories via Mirror Settings
go
gogs.io/gogs
High
about 2 months ago
Gogs Vulnerable to CSRF Leading to Organization Owner Takeover
go
gogs.io/gogs
High
about 2 months ago
Gogs has an Authentication Bypass via Unvalidated Reverse Proxy Headers
go
gogs.io/gogs
Moderate
about 2 months ago
Gogs has a Denial of Service in repository/wiki file listing web pages
go
gogs.io/gogs
High
about 2 months ago
Gogs: XSS in .ipynb files renderer due to outdated notebookjs
go
gogs.io/gogs
High
about 2 months ago
Gogs: Overwriting critical files results in a denial of service
go
gogs.io/gogs
Moderate
5 months ago
Gogs: Access tokens get exposed through URL params in API requests
go
gogs.io/gogs
Moderate
5 months ago
Gogs: Stored XSS in branch and wiki views through author and committer names
go
gogs.io/gogs
Critical
5 months ago
Gogs: Cross-repository LFS object overwrite via missing content hash verification
go
gogs.io/gogs
Moderate
6 months ago
Gogs has an Authorization Bypass Allows Cross-Repository Label Modification in Gogs
go
gogs.io/gogs
Moderate
6 months ago
Gogs Allows Cross-Repository Comment Deletion via DeleteComment
go
gogs.io/gogs
High
6 months ago
Gogs vulnerable to arbitrary file deletion via Path Traversal in wiki page update
go
gogs.io/gogs
Moderate
6 months ago
Gogs has arbitrary file read/write via Path Traversal in Git hook editing
go
gogs.io/gogs
Moderate
6 months ago
Gogs user can update repository content with read-only permission
go
gogs.io/gogs
Critical
6 months ago
Gogs's update .git/config file allows remote command execution
go
gogs.io/gogs
Likely fork
Critical
about 1 year ago
Gogs allows deletion of internal files which leads to remote command execution
go
gogs.io/gogs
Critical
over 1 year ago
Gogs allows argument injection during the previewing of changes
go
gogs.io/gogs
Moderate
about 4 years ago
Cross-site Scripting vulnerability in repository issue list in Gogs
go
gogs.io/gogs