CVE-2020-14958: Medium severity Gogs Gogs vulnerability
Published Jun 21, 2020
·Updated
In Gogs 0.11.91, MakeEmailPrimary in models/usermail.go lacks a "not the owner of the email" check.
Affected Software
1 affected component
Gogs Gogs=0.11.91
Remediation
Patch Available
Event History
Jun 21, 2020
CVE Published
via MITRE·07:57 PM
Data Sourced
via MITRE·07:57 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2020-14958.
2
What is the severity of CVE-2020-14958?
The severity of CVE-2020-14958 is medium (6.5).
3
What software versions are affected by CVE-2020-14958?
Gogs version 0.11.91 is affected by CVE-2020-14958.
4
How can I fix CVE-2020-14958?
To fix CVE-2020-14958, update Gogs to a version that includes the fix, such as version 0.11.92 or later.
5
Where can I find more information about CVE-2020-14958?
You can find more information about CVE-2020-14958 on the GitHub commit (https://github.com/gogs/gogs/commit/82ff0c5852f29daa5f95d965fd50665581e7ea3c) and pull request (https://github.com/gogs/gogs/pull/5988) related to the fix.