Gogs patches critical zero-day enabling remote code execution
ID: 5a9adaf9-d728-5656-9d67-aa4a36b900cf
STIX ID: report--5a9adaf9-d728-5656-9d67-aa4a36b900cf
Feed Name: Bleeping Computer
Threat Score
Rapid7 disclosed a critical argument-injection zero-day in Gogs that can be exploited by users (easy to obtain on default installs with open registration) to compromise servers, read or modify any repositories including private ones, and move laterally; Gogs issued patch 0.14.3 and recommended mitigations (disable registration, limit repo creation, audit rebase merge settings), while thousands of Gogs instances remain Internet-exposed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
