CVE-2018-16409: SSRF
Published Sep 3, 2018
·Updated
In Gogs 0.11.53, an attacker can use migrate to send arbitrary HTTP GET requests, leading to SSRF.
Affected Software
1 affected component
Gogs Gogs=0.11.53
Event History
Sep 3, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is CVE-2018-16409?
CVE-2018-16409 is a vulnerability in Gogs 0.11.53 that allows an attacker to send arbitrary HTTP GET requests, leading to Server-Side Request Forgery (SSRF).
2
How severe is CVE-2018-16409?
CVE-2018-16409 is considered high severity with a CVSS score of 8.6 out of 10.
3
How can an attacker exploit CVE-2018-16409?
An attacker can exploit CVE-2018-16409 by using the 'migrate' feature in Gogs 0.11.53 to send arbitrary HTTP GET requests.
4
What is Server-Side Request Forgery (SSRF)?
Server-Side Request Forgery (SSRF) is a vulnerability that allows an attacker to make requests from the vulnerable server to internal resources or external systems.
5
Is there a fix available for CVE-2018-16409?
Yes, the fix for CVE-2018-16409 is to update Gogs to a version higher than 0.11.53.