First published: Sat Feb 25 2023(Updated: )
OS Command Injection in GitHub repository gogs/gogs prior to 0.12.11.
Credit: security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
Gogs Gogs | <0.12.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability severity of CVE-2022-2024 is critical.
To fix the OS Command Injection vulnerability in GitHub repository gogs/gogs CVE-2022-2024, upgrade to version 0.12.11 or higher.
Versions of Gogs Gogs prior to 0.12.11 are affected by CVE-2022-2024.
The Common Weakness Enumeration (CWE) ID associated with CVE-2022-2024 is CWE-77 and CWE-78.
More information about CVE-2022-2024 can be found at the following references: - [GitHub Commit](https://github.com/gogs/gogs/commit/15d0d6a94be0098a8227b6b95bdf2daed105ec41) - [Huntr Dev Bounty](https://huntr.dev/bounties/18cf9256-23ab-4098-a769-85f8da130f97)