CVE-2018-15192

Severity CVSS v4.0:
Pending analysis
Type:
CWE-918 Server-Side Request Forgery (SSRF)
Publication date:
08/08/2018
Last modified:
18/10/2018

Description

An SSRF vulnerability in webhooks in Gitea through 1.5.0-rc2 and Gogs through 0.11.53 allows remote attackers to access intranet services.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gitea:gitea:*:*:*:*:*:*:*:* 1.5.0 (excluding)
cpe:2.3:a:gitea:gitea:1.5.0:rc1:*:*:*:*:*:*
cpe:2.3:a:gitea:gitea:1.5.0:rc2:*:*:*:*:*:*
cpe:2.3:a:gogs:gogs:*:*:*:*:*:*:*:* 0.11.53 (including)