CVE-2018-15192: SSRF
An SSRF vulnerability in webhooks in Gitea through 1.5.0-rc2 and Gogs through 0.11.53 allows remote attackers to access intranet services.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this SSRF vulnerability in webhooks?
The vulnerability ID for this SSRF vulnerability in webhooks is CVE-2018-15192.
What is the affected software for this vulnerability?
The affected software for this vulnerability includes Gitea versions up to 1.5.0-rc2 and Gogs versions up to 0.11.53.
What is the severity of CVE-2018-15192?
The severity of CVE-2018-15192 is rated as high with a score of 8.6 out of 10.
How can remote attackers exploit this vulnerability?
Remote attackers can exploit this vulnerability to access intranet services.
Are there any references available for this vulnerability?
Yes, there are references available for this vulnerability. You can find them at the following links: [NVD](https://nvd.nist.gov/vuln/detail/CVE-2018-15192), [Gitea GitHub Issue](https://github.com/go-gitea/gitea/issues/4624), [Gogs GitHub Issue](https://github.com/gogs/gogs/issues/5366).