blob: 5aabdfb781681e38d032dde28a767831ea2c5061 [file] [log] [blame]
id: GO-2022-0471
modules:
- module: gogs.io/gogs
versions:
- fixed: 0.12.8
vulnerable_at: 0.12.8-rc.1
summary: OS Command Injection in gogs in gogs.io/gogs
cves:
- CVE-2021-32546
ghsas:
- GHSA-56j7-2pm8-rgmx
references:
- advisory: https://github.com/gogs/gogs/security/advisories/GHSA-56j7-2pm8-rgmx
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2021-32546
- web: https://github.com/gogs/gogs/blob/f36eeedbf89328ee70cc3a2e239f6314f9021f58/conf/app.ini#L127-L129
- web: https://github.com/gogs/gogs/issues/6555
- web: https://github.com/gogs/gogs/pull/6986
- web: https://github.com/gogs/gogs/releases
- web: https://github.com/gogs/gogs/releases/tag/v0.12.8
source:
id: GHSA-56j7-2pm8-rgmx
created: 2024-08-20T14:00:01.410991-04:00
review_status: UNREVIEWED
unexcluded: NOT_IMPORTABLE