Critical RCE Vulnerability Affects Gogs: No Solution Available, Exploit Released

Gogs RCE Vulnerability: A Major Issue Without a Fix in Sight

A significant vulnerability exists in Gogs, the open-source Git platform that has everyone on edge. This serious RCE (remote code execution) flaw can be leveraged by any authenticated user—no unique privileges required. It’s akin to leaving the door ajar for anyone to tamper with your server. We’re looking at compromised systems, hijacked credentials, and altered code in repositories. A complete disaster, if you ask me.

Bug Information and Absence of a Patch

A security expert identified this 9.4-scored issue and informed the Gogs team back in March. However, no patch has surfaced yet. In the meantime, there’s a Metasploit module circulating, so you can bet people will soon attempt to exploit it. Thanks to Jonah Burgess from Rapid7 for discovering the issue and trying to notify the Gogs team via GitHub. But since March 28, all he’s received is silence. Gogs has been as responsive as a brick wall.

No Response from Gogs or DigitalOcean

Burgess even offered a proposed fix on a silver platter, but it’s remained unaddressed. Meanwhile, Gogs sponsor DigitalOcean has vanished as well—no updates on when they intend to resolve this security crisis. It’s an argument injection flaw in Gogs’ pull request merge process, originating from the Merge() function in internal/database/pull.go. Just what you needed, right?

Exploitation Mechanics

If you’re the adventurous type who enables “Rebase before merging”, reconsider. This vulnerability allows attackers to submit branch names directly to a git rebase command, and soon enough, your server is under their control. Burgess even developed an exploit to function across Windows, Linux, and macOS, just to cover all bases.

Protect Yourself While You Can

While the experts at Gogs sort this out, it’s wise to take some preventive measures. First, disable user registration (DISABLE_REGISTRATION = true in app.ini) to prevent any random individual from creating accounts. Restrict repository creation (MAX_CREATION_LIMIT = 0 in app.ini) so users can’t easily create their own with rebase enabled. However, don’t feel too secure; users with write permissions to current repositories can still find a way to exploit. Lastly, review those rebase merge settings and disable “Rebase before merging” under Settings > Advanced. But keep in mind, a clever user with admin privileges can simply turn it back on.

A Cautionary Note

So, to all Gogs users, stay alert. There’s no definitive solution yet, but don’t let that hinder you from dodging any potential threats. Until something changes, remain vigilant, stay informed, and don’t let your servers become easy targets.

Summary: Gogs Vulnerability Persists

A significant vulnerability exists, and there’s little urgency to fix it. Stay on guard, or you could find yourself in a tricky situation.