CVE-2022-1986: OS Command Injection in gogs/gogs
Published Jun 9, 2022
·Updated
OS Command Injection in GitHub repository gogs/gogs prior to 0.12.9.
Affected Software
1 affected component
Gogs Gogs<0.12.9
Remediation
Event History
Jun 9, 2022
CVE Published
via MITRE·03:35 AM
Data Sourced
via MITRE·03:35 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-1986?
CVE-2022-1986 is an OS Command Injection vulnerability in the GitHub repository gogs/gogs prior to version 0.12.9.
2
What is the severity of CVE-2022-1986?
CVE-2022-1986 has a severity rating of critical.
3
How does CVE-2022-1986 impact the Gogs software?
CVE-2022-1986 allows attackers to execute arbitrary commands on the affected Gogs software.
4
How can I fix CVE-2022-1986?
To fix CVE-2022-1986, update the Gogs software to version 0.12.9 or later.
5
Where can I find more information about CVE-2022-1986?
You can find more information about CVE-2022-1986 at the following references: [GitHub commit](https://github.com/gogs/gogs/commit/38aff73251cc46ced96dd608dab6190415032a82) and [Huntr bounty](https://huntr.dev/bounties/776e8f29-ff5e-4501-bb9f-0bd335007930).