-
Notifications
You must be signed in to change notification settings - Fork 5.1k
Remote command execution #5469
Copy link
Copy link
Closed
Labels
priority: criticalOh damn, fix it now!Oh damn, fix it now!status: needs feedbackTell me more about itTell me more about it💊 bugSomething isn't workingSomething isn't working🔒 securityCategorizes as related to securityCategorizes as related to security🤷 third-partyIt's someone else's shitIt's someone else's shit
Description
- Gogs version (or commit ref): newest(3a4c981)
- Can you reproduce the bug at https://try.gogs.io:
- [ x] Yes (provide example URL)
- No
- Not relevant
Description
I can login to arbitrary account. And when I logged in as admin, I can execute any command by git hooks.
I just tried login to Unknown's account but do not perform command execution.
As this is a very severe issue, I won't post details here.
@unknwon can you give me your email address and I send the details to you?
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
priority: criticalOh damn, fix it now!Oh damn, fix it now!status: needs feedbackTell me more about itTell me more about it💊 bugSomething isn't workingSomething isn't working🔒 securityCategorizes as related to securityCategorizes as related to security🤷 third-partyIt's someone else's shitIt's someone else's shit

