CVE-2018-18925: Critical severity Gogs Gogs vulnerability
Published Nov 4, 2018
·Updated
Gogs 0.11.66 allows remote code execution because it does not properly validate session IDs, as demonstrated by a ".." session-file forgery in the file session provider in file.go. This is related to session ID handling in the go-macaron/session code for Macaron.
Affected Software
1 affected component
Gogs Gogs<=0.11.66
Remediation
Patch Available
Event History
Nov 4, 2018
CVE Published
05:29 AM
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID is CVE-2018-18925.
2
What is the severity level of CVE-2018-18925?
The severity level of CVE-2018-18925 is critical.
3
How does CVE-2018-18925 allow remote code execution?
CVE-2018-18925 allows remote code execution by not properly validating session IDs, allowing for a session-file forgery.
4
What version of Gogs is affected by CVE-2018-18925?
Gogs version 0.11.66 is affected by CVE-2018-18925.
5
Is there a fix available for CVE-2018-18925?
Yes, a fix is available for CVE-2018-18925. Please refer to the provided reference for more information.