Two months after Rapid7 discovered the hole in the Git service, the project maintainer has yet to patch the bug.

Two months after Rapid7 discovered the hole in the Git service, the project maintainer has yet to patch the bug.

An unpatched zero-day vulnerability in the Gogs self-hosted Git service can allow attackers to gain remote code execution (RCE) on Internet-facing instances.

Gogs 9.4 CVSS flaw exploits git rebase injection on 1,141 exposed instances, enabling remote code execution.

Angreifer können Gogs-Server in den Standardeinstellungen mit Schadcode attackieren. Bislang können Admins Systeme nur über einen Workaround schützen.

Open source Git service Gogs is affected by a critical-severity zero-day vulnerability that exposes servers to remote code execution.

Researcher reported the vuln in March. Maintainers haven't responded to his messages since