VDB
Sign up
MEDIUM6.5

GHSA-mr6h-chqp-p9g2

SQL Injection in gogs.io/gogs

Quick fix

GHSA-mr6h-chqp-p9g2 — gogs.io/gogs: upgrade to the fixed version with the command below.

go get gogs.io/gogs@v0.5.8

Details

SQL injection vulnerability in the GetIssues function in models/issue.go in Gogs (aka Go Git Service) 0.3.1-9 through 0.5.6.x before 0.5.6.1025 Beta allows remote attackers to execute arbitrary SQL commands via the label parameter to user/repos/issues.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/gogs.io/gogs
Introduced in: 0.3.1Fixed in: 0.5.8
Fixgo get gogs.io/gogs@v0.5.8
Go/github.com/gogits/gogs
Introduced in: 0.3.1Fixed in: 0.5.8
Fixgo get github.com/gogits/gogs@v0.5.8

References