First published: Mon Sep 03 2018(Updated: )
In Gogs 0.11.53, an attacker can use migrate to send arbitrary HTTP GET requests, leading to SSRF.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Gogs Gogs | =0.11.53 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-16409 is a vulnerability in Gogs 0.11.53 that allows an attacker to send arbitrary HTTP GET requests, leading to Server-Side Request Forgery (SSRF).
CVE-2018-16409 is considered high severity with a CVSS score of 8.6 out of 10.
An attacker can exploit CVE-2018-16409 by using the 'migrate' feature in Gogs 0.11.53 to send arbitrary HTTP GET requests.
Server-Side Request Forgery (SSRF) is a vulnerability that allows an attacker to make requests from the vulnerable server to internal resources or external systems.
Yes, the fix for CVE-2018-16409 is to update Gogs to a version higher than 0.11.53.