CVE-2022-1285: Server-Side Request Forgery (SSRF) in gogs/gogs
Published Jun 1, 2022
·Updated
Server-Side Request Forgery (SSRF) in GitHub repository gogs/gogs prior to 0.12.8.
Affected Software
1 affected component
Gogs Gogs<0.12.8
Remediation
Event History
Jun 1, 2022
CVE Published
via MITRE·05:55 AM
Data Sourced
via MITRE·05:55 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-1285?
The severity of CVE-2022-1285 is high.
2
What is CVE-2022-1285?
CVE-2022-1285 is a Server-Side Request Forgery (SSRF) vulnerability in the GitHub repository gogs/gogs prior to version 0.12.8.
3
How does CVE-2022-1285 affect Gogs Gogs?
CVE-2022-1285 affects Gogs Gogs versions prior to 0.12.8.
4
How do I fix CVE-2022-1285?
To fix CVE-2022-1285, update Gogs Gogs to version 0.12.8 or later.
5
Where can I find more information about CVE-2022-1285?
You can find more information about CVE-2022-1285 at the following references: [GitHub commit](https://github.com/gogs/gogs/commit/7885f454a4946c4bbec1b4f8c603b5eea7429c7f), [Huntr.dev bounty](https://huntr.dev/bounties/da1fbd6e-7a02-458e-9c2e-6d226c47046d).