First published: Fri Mar 11 2022(Updated: )
Missing Authorization in GitHub repository gogs/gogs prior to 0.12.5.
Credit: security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
Gogs Gogs | <0.12.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-0871 is critical, with a severity value of 9.1.
The software version prior to 0.12.5 of Gogs Gogs is affected by CVE-2022-0871.
To fix CVE-2022-0871, update your Gogs Gogs installation to version 0.12.5 or above.
You can find more information about CVE-2022-0871 at the following references: [https://github.com/gogs/gogs/commit/64102be2c90e1b47dbdd379873ba76c80d4b0e78](https://github.com/gogs/gogs/commit/64102be2c90e1b47dbdd379873ba76c80d4b0e78) and [https://huntr.dev/bounties/ea82cfc9-b55c-41fe-ae58-0d0e0bd7ab62](https://huntr.dev/bounties/ea82cfc9-b55c-41fe-ae58-0d0e0bd7ab62).
The Common Weakness Enumeration (CWE) for CVE-2022-0871 is CWE-862.