CVE-2022-2024: OS Command Injection in gogs/gogs
Published Feb 25, 2023
·Updated
OS Command Injection in GitHub repository gogs/gogs prior to 0.12.11.
Affected Software
1 affected component
Gogs Gogs<0.12.11
Remediation
Event History
Feb 25, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability severity of CVE-2022-2024?
The vulnerability severity of CVE-2022-2024 is critical.
2
How can I fix the OS Command Injection vulnerability in GitHub repository gogs/gogs CVE-2022-2024?
To fix the OS Command Injection vulnerability in GitHub repository gogs/gogs CVE-2022-2024, upgrade to version 0.12.11 or higher.
3
What software versions are affected by CVE-2022-2024?
Versions of Gogs Gogs prior to 0.12.11 are affected by CVE-2022-2024.
4
What is the Common Weakness Enumeration (CWE) ID associated with CVE-2022-2024?
The Common Weakness Enumeration (CWE) ID associated with CVE-2022-2024 is CWE-77 and CWE-78.
5
Where can I find more information about CVE-2022-2024?
More information about CVE-2022-2024 can be found at the following references: - [GitHub Commit](https://github.com/gogs/gogs/commit/15d0d6a94be0098a8227b6b95bdf2daed105ec41) - [Huntr Dev Bounty](https://huntr.dev/bounties/18cf9256-23ab-4098-a769-85f8da130f97)