← back
CVE-2022-0415criticalCWE-20

Remote Command Execution in uploading repository file in gogs/gogs

55Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendcvss 9.9epss 65%
exploitation probability
65%top 1% of all CVEs
observed exploitation
nono source reports it
Remote Command Execution in uploading repository file in GitHub repository gogs/gogs prior to 0.12.6.
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected products
gogs · gogs/gogs