CVE-2019-14544: Critical severity Gogs Gogs vulnerability
Published Aug 2, 2019
·Updated
routes/api/v1/api.go in Gogs 0.11.86 lacks permission checks for routes: deploy keys, collaborators, and hooks.
Affected Software
1 affected component
Gogs Gogs=0.11.86
Remediation
Patch Available
Event History
Aug 2, 2019
CVE Published
via MITRE·09:17 PM
Data Sourced
via MITRE·09:17 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2019-14544.
2
What is the severity of CVE-2019-14544?
The severity of CVE-2019-14544 is critical with a score of 9.8.
3
What software is affected by CVE-2019-14544?
Gogs version 0.11.86 is affected by CVE-2019-14544.
4
What are some potential risks of CVE-2019-14544?
CVE-2019-14544 can result in unauthorized access to deploy keys, collaborators, and hooks in Gogs.
5
How can I fix CVE-2019-14544?
To fix CVE-2019-14544, update Gogs to a version that includes the necessary permission checks for routes.