FixVibe

// 코드 / 스포트라이트

Gogs Directory Traversal Dependency Advisory

An affected Gogs runtime can put file-upload path handling on a traversal boundary.

What it is

Self-hosted Git services sit close to source code, automation tokens, and deployment workflows. A path traversal advisory in Gogs should be treated as a runtime upgrade item when the affected version is part of the deployed service.

How it happens

CVE-2018-20303 is a directory traversal in Gogs's file-upload handling, fixed in Gogs 0.11.82.1218. A crafted upload path lets the file land outside the upload directory on the server.

What an attacker gets

An attacker who can upload files to an affected Gogs server may be able to write files outside the intended directory, on the machine that holds your repositories, deploy keys, and automation tokens.

// what fixvibe reports

What FixVibe reports

Runs when you connect a GitHub repository, on Pro and above. Each finding shows the file and line, its severity and fix steps you can paste into your AI coding tool.

How to fix it

Upgrade Gogs to 0.11.82.1218 or newer, or to a build that includes commit ff93d9dbda5c, regenerate Go module or Dep lock metadata, rebuild the deployed Gogs runtime, and verify the running service reports the patched version before closing the advisory.

// 내 앱에서 직접 실행해보세요

FixVibe가 지켜보는 동안 계속 배포하세요.

Connect a GitHub repo to check its code, dependencies and workflows.

소스 코드
198
이 카테고리에서 실행되는 테스트
모듈
155
전용 소스 코드 검사
GitHub repos
190+
checks on each connected repo
Connect GitHub →

// 최신 체크 · 실용적인 수정 · 자신 있게 배포

Gogs Directory Traversal Dependency Advisory: what it is and how to fix it · FixVibe