CVE-2022-0871: Missing Authorization in gogs/gogs
Published Mar 11, 2022
·Updated
Missing Authorization in GitHub repository gogs/gogs prior to 0.12.5.
Affected Software
1 affected component
Gogs Gogs<0.12.5
Remediation
Event History
Mar 11, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-0871?
The severity of CVE-2022-0871 is critical, with a severity value of 9.1.
2
What software versions are affected by CVE-2022-0871?
The software version prior to 0.12.5 of Gogs Gogs is affected by CVE-2022-0871.
3
How do I fix CVE-2022-0871?
To fix CVE-2022-0871, update your Gogs Gogs installation to version 0.12.5 or above.
4
Where can I find more information about CVE-2022-0871?
You can find more information about CVE-2022-0871 at the following references: [https://github.com/gogs/gogs/commit/64102be2c90e1b47dbdd379873ba76c80d4b0e78](https://github.com/gogs/gogs/commit/64102be2c90e1b47dbdd379873ba76c80d4b0e78) and [https://huntr.dev/bounties/ea82cfc9-b55c-41fe-ae58-0d0e0bd7ab62](https://huntr.dev/bounties/ea82cfc9-b55c-41fe-ae58-0d0e0bd7ab62).
5
What is the Common Weakness Enumeration (CWE) for CVE-2022-0871?
The Common Weakness Enumeration (CWE) for CVE-2022-0871 is CWE-862.