Server-Side Request Forgery (SSRF) in gogs - CVE-2018-16409
Published: September 3, 2018 / Updated: August 8, 2020
Vulnerability identifier: #VU36735
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N]
CVE-ID: CVE-2018-16409
CWE-ID: CWE-918
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
In Gogs 0.11.53, an attacker can use migrate to send arbitrary HTTP GET requests, leading to SSRF.
Affected software
gogs
How to mitigate CVE-2018-16409
Install update from vendor's website.