Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:7683
HistoryNov 05, 2018 - 1:57 a.m.

Remote Code Execution (RCE)

2018-11-0501:57:12
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10

0.098 Low

EPSS

Percentile

94.9%

github.com/gogs/gogs is vulnerable to remote code execution (RCE) attacks. The vulnerability exists due to the ability to forge a session-file in file.go, allowing unauthenticated users to obtain an admin session, and subsequently allowing remote code to be injected.

0.098 Low

EPSS

Percentile

94.9%