Warning: foreach() argument must be of type array|object, false given in /home/u750883576/domains/esl-news.com/public_html/wp-content/plugins/gpt-post-quiz/includes/admin/class-gpoq-admin-4.php on line 450
Warning: foreach() argument must be of type array|object, false given in /home/u750883576/domains/esl-news.com/public_html/wp-content/plugins/td-composer/legacy/common/wp_booster/td_menu.php on line 88
A serious security problem has been found in Gogs, a popular open-source tool for managing code. This problem lets a user run harmful code on the server under certain conditions.
Rapid7, a security company, says this flaw has a score of 9.4. It does not have a special identifier called CVE. The issue happens when a user creates a request with a dangerous name. This can cause the server to run a command that it should not.
Any registered user can create a repo, which is a place to store code. If they turn on a setting called rebase, they can use this flaw quickly and easily. In some cases, a user with access to a repository can also use this problem to run harmful code.
As of now, there is no fix for this issue. It has been reported to the Gogs team. If someone uses this flaw successfully, they can access all repositories and private information.
Rapid7 advises users to stop new registrations and restrictrepository creation to fix this issue until a patch is available.