Skip to content

Remote Code Execution #5569

@snyff

Description

@snyff

The vulnerability impacting Gogs also impacts gitea
gogs/gogs#5558

Description

By using upload file with a malicious filename, an attacker is able to become any users and then gain code execution using hooks.

Gogs already worked on the issue in their develop branch

Screenshots

Me logged in as user_id 1

screen shot 2018-12-20 at 1 25 13 pm

Metadata

Metadata

Assignees

No one assigned

    Labels

    topic/securitySomething leaks user information or is otherwise vulnerable. Should be fixed!

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions