Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:34654
HistoryMar 14, 2022 - 4:40 a.m.

Server-side Request Forgery (SSRF)

2022-03-1404:40:24
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7

0.001 Low

EPSS

Percentile

50.8%

github.com/gogs/gogs is vulnerable to server-side request forgery. An attacker can send malicious requests on behalf of the server into the network-internal hosts through the ParseRemoteAddr function of repo.go.

0.001 Low

EPSS

Percentile

50.8%