CVE-2022-1993
Path Traversal in gogs/gogs
Description
Path Traversal in GitHub repository gogs/gogs prior to 0.12.9.
In plain language
AI Worth attentionIf you run Gogs version prior to 0.12.9, an attacker who has basic access can trick it into reading or writing files outside its normal folders—so you should patch.
CVE-2022-1993 is a path traversal issue in gogs/gogs before 0.12.9 that allows an authenticated user with low-level privileges to manipulate file paths and read/write files outside the intended application directory over the network.
What to do now
- Check your Gogs version and confirm it is prior to 0.12.9.
- Review whether any non-admin accounts exist that could be “low-level” users in your setup.
- Upgrade Gogs to 0.12.9 or later (fixed version).
- If you cannot upgrade right away, restrict network access to Gogs and limit who can log in, then plan the upgrade immediately after.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2022-1993 and every CVE in our database. Create a free account — no credit card required.
Create Free Account