First published: Sun Nov 04 2018(Updated: )
Gogs 0.11.66 allows remote code execution because it does not properly validate session IDs, as demonstrated by a ".." session-file forgery in the file session provider in file.go. This is related to session ID handling in the go-macaron/session code for Macaron.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Gogs Gogs | <=0.11.66 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2018-18925.
The severity level of CVE-2018-18925 is critical.
CVE-2018-18925 allows remote code execution by not properly validating session IDs, allowing for a session-file forgery.
Gogs version 0.11.66 is affected by CVE-2018-18925.
Yes, a fix is available for CVE-2018-18925. Please refer to the provided reference for more information.