S4E just found a medium-severity finding from backup files scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-0870 Scanner

Detects 'Server-Side Request Forgery (SSRF)' vulnerability in gogs/gogs affects v. prior to 0.12.5.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.5k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
5.0
CVSSmedium
Exploitable remotely over the internet · low-privilege account sufficient.
Description

Server-Side Request Forgery (SSRF) in GitHub repository gogs/gogs prior to 0.12.5.

Attack Vector
Network
Privileges Req.
Low
User Interaction
None
Affected
gogs/gogsby gogs
AFFECTED< 0.12.5SAFE ✓≥ 0.12.5
Updated Sep 18, 2026View on NVD →
Detail

Gogs/Gogs is an open-source, self-hosted Git service that provides an easy and fast way to manage repos, users, and organizations. It is a lightweight and efficient alternative to GitHub that is written in Go, a language that is known for its performance and concurrency. As a distributed system, Gogs/Gogs allows users to easily manage their code repositories and version control systems.

CVE-2022-0870 is a Server-Side Request Forgery (SSRF) vulnerability that was identified in the Gogs/Gogs software prior to version 0.12.5. Specifically, this vulnerability arises from a flaw in the way that Gogs/Gogs processes certain external requests. This flaw allows an attacker to manipulate the targeted web server from an unrestricted network location, resulting in the exploitation of the server as a starting point for attacks on other systems.

When exploited, the vulnerability can have devastating consequences, including full access to sensitive data, intellectual property, and other confidential information. Additionally, attackers can use this vulnerability to inject malicious code into the targeted system, which can lead to massive data breaches, network crashes, and other security incidents.

In conclusion, it is essential that organizations take the necessary steps to protect their digital assets from vulnerabilities such as CVE-2022-0870. By being proactive and taking the necessary precautions outlined above, organizations can ensure that their systems remain secure and protected against potential attacks. Furthermore, by utilizing the pro features of the s4e.io platform, businesses can quickly and easily learn about potential vulnerabilities in their digital assets, allowing them to act quickly and decisively to address potential vulnerabilities and prevent security breaches.

 

REFERENCES

Solution Advice

Fortunately, there are a few precautions that can be taken to protect against this vulnerability in Gogs/Gogs. These include:

  • Regularly updating the software with the latest security patches and fixes
  • Using a web application firewall (WAF) to detect and prevent unauthorized network traffic
  • Disabling unnecessary network services and protocols that can be used to exploit this vulnerability
  • Using access control mechanisms such as firewalls and authentication systems to block unauthorized access to the network
  • Monitoring network traffic and system logs for unusual activity that could indicate a possible attack

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.