CVE-2022-1884
A remote command execution vulnerability exists in gogs/gogs versions <=0.12.7 when deployed on a Windows server. The vulnerability arises due to improper validation of the `tree_path` parameter during file uploads. An attacker can set `tree_path=.git.` to upload a file into the .git directory, allowing them to write or rewrite the `.git/config` file. If the `core.sshCommand` is set, this can lead to remote command execution.
- Affected products
- Gogs
- Gogs
- ≤ 0.12.7
- Fix
- Available
- CVSS 3.1
- 10.0 CRITICAL
- EPSS
- 1.8% (76th percentile)
- Weakness
- CWE-77, CWE-78
- NVD status
- Analyzed
- Published
- 2024-11-15
CVE-2022-1884 at NVD
No indexed exploits for CVE-2022-1884 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2022-1884 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.