First published: Wed Jun 01 2022(Updated: )
Server-Side Request Forgery (SSRF) in GitHub repository gogs/gogs prior to 0.12.8.
Credit: security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
Gogs Gogs | <0.12.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-1285 is high.
CVE-2022-1285 is a Server-Side Request Forgery (SSRF) vulnerability in the GitHub repository gogs/gogs prior to version 0.12.8.
CVE-2022-1285 affects Gogs Gogs versions prior to 0.12.8.
To fix CVE-2022-1285, update Gogs Gogs to version 0.12.8 or later.
You can find more information about CVE-2022-1285 at the following references: [GitHub commit](https://github.com/gogs/gogs/commit/7885f454a4946c4bbec1b4f8c603b5eea7429c7f), [Huntr.dev bounty](https://huntr.dev/bounties/da1fbd6e-7a02-458e-9c2e-6d226c47046d).