CVE-2018-20303: Path Traversal
Published Dec 20, 2018
·Updated
In pkg/tool/path.go in Gogs before 0.11.82.1218, a directory traversal in the file-upload functionality can allow an attacker to create a file under data/sessions on the server, a similar issue to CVE-2018-18925.
Affected Software
2 affected componentsFixes available
go/gogs.io/gogs<0.11.82.1218
0.11.82.1218
Gogs Gogs<0.11.82.1218
Remediation
Patch Available
Event History
Dec 20, 2018
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
May 14, 2022
Advisory Published
01:37 AM
Frequently Asked Questions
1
What is CVE-2018-20303?
CVE-2018-20303 is a vulnerability in Gogs before version 0.11.82.1218 that allows directory traversal in the file-upload functionality.
2
How severe is CVE-2018-20303?
CVE-2018-20303 has a severity value of 7.5, which is considered high.
3
Which software versions are affected by CVE-2018-20303?
The vulnerability affects Gogs versions up to, but not including, 0.11.82.1218.
4
How can I fix CVE-2018-20303?
To fix CVE-2018-20303, you should upgrade Gogs to version 0.11.82.1218 or later.
5
Where can I find more information about CVE-2018-20303?
You can find more information about CVE-2018-20303 at the following references: [1] [2] [3]