CVE-2014-8681: SQL Injection
Published Nov 21, 2014
·Updated
SQL injection vulnerability in the GetIssues function in models/issue.go in Gogs (aka Go Git Service) 0.3.1-9 through 0.5.6.x before 0.5.6.1025 Beta allows remote attackers to execute arbitrary SQL commands via the label parameter to user/repos/issues.
Affected Software
8 affected componentsFixes available
go/github.com/gogits/gogs>=0.3.1<0.5.8
0.5.8
go/gogs.io/gogs>=0.3.1<0.5.8
0.5.8
Gogits Gogs<=0.5.5
Gogits Gogs=0.3.1-9
Gogits Gogs=0.4.1
Gogits Gogs=0.4.2
Gogits Gogs=0.5.0
Gogits Gogs=0.5.2
Event History
Nov 21, 2014
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Jun 29, 2021
Advisory Published
06:32 PM
Frequently Asked Questions
1
What is the severity of CVE-2014-8681?
CVE-2014-8681 has a medium severity rating due to its potential for remote SQL injection attacks.
2
How do I fix CVE-2014-8681?
To fix CVE-2014-8681, upgrade Gogs to version 0.5.8 or later.
3
What software versions are affected by CVE-2014-8681?
CVE-2014-8681 affects Gogs versions from 0.3.1-9 to 0.5.6.x, excluding 0.5.8.
4
What type of vulnerability is CVE-2014-8681?
CVE-2014-8681 is classified as an SQL injection vulnerability.
5
Can CVE-2014-8681 be exploited remotely?
Yes, CVE-2014-8681 can be exploited by remote attackers to execute arbitrary SQL commands.