cloudfoundry-community / gogs-boshrelease

Gogs is a painless self-hosted Git service
https://gogs.io/
Apache License 2.0
5 stars 5 forks source link

Command Injection Vulnerability #3

Closed squeedee closed 7 years ago

squeedee commented 7 years ago

This exploit exists in this project. We've highlighted the affected lines

Details in this report

gogs-boshrelease https://github.com/cloudfoundry-community/gogs-boshrelease/blob/master/src/common/utils.sh#L4-L5

jrbudnack commented 7 years ago

@squeedee Thank you for letting us know! I just fixed it in the latest version of the release.