CVE-2020-15867: High severity Gogs Gogs vulnerability
The git hook feature in Gogs 0.5.5 through 0.12.2 allows for authenticated remote code execution. There can be a privilege escalation if access to this hook feature is granted to a user who does not have administrative privileges. NOTE: because this is mentioned in the documentation but not in the UI, it could be considered a "Product UI does not Warn User of Unsafe Actions" issue.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-15867?
CVE-2020-15867 is a vulnerability in the git hook feature of Gogs 0.5.5 through 0.12.2 that allows for authenticated remote code execution.
What is the severity of CVE-2020-15867?
The severity of CVE-2020-15867 is high with a CVSS score of 7.2.
How does CVE-2020-15867 affect Gogs?
CVE-2020-15867 affects Gogs versions 0.5.5 through 0.12.2 by allowing authenticated users to execute remote code through the git hook feature.
Can an attacker escalate privileges through CVE-2020-15867?
Yes, there can be a privilege escalation if a user without administrative privileges is granted access to the git hook feature.
How can I fix CVE-2020-15867?
To fix CVE-2020-15867, users are recommended to update Gogs to a version that is not affected, or apply any patches or security updates provided by the Gogs development team.