First published: Thu Jun 09 2022(Updated: )
OS Command Injection in GitHub repository gogs/gogs prior to 0.12.9.
Credit: security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
Gogs Gogs | <0.12.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-1986 is an OS Command Injection vulnerability in the GitHub repository gogs/gogs prior to version 0.12.9.
CVE-2022-1986 has a severity rating of critical.
CVE-2022-1986 allows attackers to execute arbitrary commands on the affected Gogs software.
To fix CVE-2022-1986, update the Gogs software to version 0.12.9 or later.
You can find more information about CVE-2022-1986 at the following references: [GitHub commit](https://github.com/gogs/gogs/commit/38aff73251cc46ced96dd608dab6190415032a82) and [Huntr bounty](https://huntr.dev/bounties/776e8f29-ff5e-4501-bb9f-0bd335007930).