Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:20985
HistoryAug 05, 2019 - 3:01 a.m.

Missing Permission Checks

2019-08-0503:01:04
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6

0.002 Low

EPSS

Percentile

60.5%

github.com/gogs/gogs is vulnerable to missing permission checks. The function RegisterRoutes in routes/api/v1/api.g does not invoke the reqAdmin method to perform permission checks for deploy keys, collaborators, and hooks.

0.002 Low

EPSS

Percentile

60.5%