QID 982551
QID 982551: Go (go) Security Update for gogs.io/gogs (GHSA-4c7m-vv47-7c69)
In Gogs 0.11.91, MakeEmailPrimary in models/user_mail.go lacks a "not the owner of the email" check.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-4c7m-vv47-7c69 for updates pertaining to this vulnerability.
Vendor References
- GHSA-4c7m-vv47-7c69 -
github.com/advisories/GHSA-4c7m-vv47-7c69
CVEs related to QID 982551
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-4c7m-vv47-7c69 | gogs.io/gogs |
|