{"id":"GHSA-fg3x-rwq9-74cw","summary":"Gogs and Gitea SSRF Vulnerability","details":"An SSRF vulnerability in webhooks in Gitea through 1.5.0-rc2 and Gogs through 0.11.53 allows remote attackers to access intranet services.","aliases":["CVE-2018-15192","GO-2023-1971"],"modified":"2024-08-20T20:58:50.794981Z","published":"2022-05-14T02:20:32Z","database_specific":{"github_reviewed_at":"2023-07-25T19:19:22Z","nvd_published_at":"2018-08-08T02:29:00Z","cwe_ids":["CWE-918"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-15192"},{"type":"WEB","url":"https://github.com/go-gitea/gitea/issues/4624"},{"type":"WEB","url":"https://github.com/gogs/gogs/issues/5366"},{"type":"WEB","url":"https://github.com/go-gitea/gitea/pull/17482"},{"type":"WEB","url":"https://github.com/gogs/gogs/pull/6002"},{"type":"WEB","url":"https://github.com/go-gitea/gitea/commit/599ff1c054e436daa4dc3f049aa8661d9c2395f9"},{"type":"WEB","url":"https://github.com/gogs/gogs/commit/22717a1c064511cf37c46af5e650baf7184cf25b"}],"affected":[{"package":{"name":"code.gitea.io/gitea","ecosystem":"Go","purl":"pkg:golang/code.gitea.io/gitea"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.16.0-rc1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-fg3x-rwq9-74cw/GHSA-fg3x-rwq9-74cw.json"}},{"package":{"name":"gogs.io/gogs","ecosystem":"Go","purl":"pkg:golang/gogs.io/gogs"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.12.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-fg3x-rwq9-74cw/GHSA-fg3x-rwq9-74cw.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"}]}