{"id":"CVE-2020-15867","details":"The git hook feature in Gogs 0.5.5 through 0.12.2 allows for authenticated remote code execution. There can be a privilege escalation if access to this hook feature is granted to a user who does not have administrative privileges. NOTE: because this is mentioned in the documentation but not in the UI, it could be considered a \"Product UI does not Warn User of Unsafe Actions\" issue.","modified":"2026-08-07T15:11:51.831800Z","published":"2020-10-16T14:15:11.627Z","references":[{"type":"EVIDENCE","url":"http://packetstormsecurity.com/files/162123/Gogs-Git-Hooks-Remote-Code-Execution.html"},{"type":"EVIDENCE","url":"https://www.fzi.de/en/news/news/detail-en/artikel/fsa-2020-3-schwachstelle-in-gitea-1125-und-gogs-0122-ermoeglicht-ausfuehrung-von-code-nach-authent/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/gogs/gogs","events":[{"introduced":"54930c001df8316d8dfda450b5c39379df2cc1b1"},{"last_affected":"253b2bef4c26925d2fd0555aa8911cd21fb68b8c"}],"database_specific":{"cpe":"cpe:2.3:a:gogs:gogs:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0.5.5"},{"last_affected":"0.12.2"}],"source":"CPE_RANGE"}}],"versions":["v0.12.2","v0.12.1","v0.12.0","v0.11.91","v0.11.86","v0.11.79","v0.11.66","v0.11.53","v0.11.43","v0.11.34","v0.11.33","v0.11.29","v0.11.19","v0.11.4","v0.11","v0.11rc","v0.10.18","v0.10.8","v0.10","v0.10rc","v0.9.141","v0.9.128","v0.9.113","v0.9.97","v0.9.71","v0.9.60","v0.9.48","v0.9.46","v0.9.13","v0.9.0","v0.8.43","v0.8.25","v0.8.10","v0.8.0","v0.7.33","v0.7.22","v0.7.19","v0.7.6","v0.7.0","v0.6.15","v0.6.9","v0.6.3","v0.6.1","v0.5.13","v0.5.11","v0.5.9","v0.5.8","v0.5.5"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-15867.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"}]}