First published: Wed Aug 08 2018(Updated: )
An SSRF vulnerability in webhooks in Gitea through 1.5.0-rc2 and Gogs through 0.11.53 allows remote attackers to access intranet services.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Gitea Gitea | <1.5.0 | |
Gitea Gitea | =1.5.0-rc1 | |
Gitea Gitea | =1.5.0-rc2 | |
Gogs Gogs | <=0.11.53 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this SSRF vulnerability in webhooks is CVE-2018-15192.
The affected software for this vulnerability includes Gitea versions up to 1.5.0-rc2 and Gogs versions up to 0.11.53.
The severity of CVE-2018-15192 is rated as high with a score of 8.6 out of 10.
Remote attackers can exploit this vulnerability to access intranet services.
Yes, there are references available for this vulnerability. You can find them at the following links: [NVD](https://nvd.nist.gov/vuln/detail/CVE-2018-15192), [Gitea GitHub Issue](https://github.com/go-gitea/gitea/issues/4624), [Gogs GitHub Issue](https://github.com/gogs/gogs/issues/5366).