CVE-2022-0415 describes a critical Remote Command Execution vulnerability affecting Gogs prior to version 0.12.6, specifically within the repository file upload functionality. With a CVSS score of 8.8 (HIGH), this flaw allows authenticated attackers to execute arbitrary commands remotely with low attack complexity, leading to high impacts on confidentiality, integrity, and availability. While no active exploitation or public Metasploit/ExploitDB modules are reported, a Nuclei template exists, and the vulnerability has a very high EPSS score, indicating a significant likelihood of future exploitation despite minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.12.6CPE matchmatch criteria | cpe:2.3:a:gogs:gogs:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.