Executive brief
Gogs is a self-hosted Git service used by developers to manage source code. A vulnerability in its file-upload system allows an attacker to bypass folder restrictions and create unauthorized files on the server. This could potentially allow an attacker to interfere with user sessions or system operations.
Technical details
A directory traversal vulnerability exists in the file-upload functionality of Gogs within 'pkg/tool/path.go'. By exploiting improper validation of user-supplied paths (CWE-22), a remote, unauthenticated attacker can upload files to locations outside the intended directory. Specifically, this can be used to place files within the 'data/sessions' directory on the server. This issue is similar to CVE-2018-18925 and was addressed in version 0.11.82.1218.
Affected products
- Gogs Gogs < 0.11.82.1218
Timeline
- 2018-12-20: disclosed: NVD publication date
- 2018-12-18: patched: Date of the fix commit and patched version release
- 2022-05-14: advisory: GitHub Advisory published