MEDIUM 5.3 Go
Insecure Permissions in Gogs
GHSA-4c7m-vv47-7c69 · CVE-2020-14958 · GO-2022-0788
Published · Modified
Description
In Gogs 0.11.91, MakeEmailPrimary in models/user_mail.go lacks a "not the owner of the email" check.
Ready to move
Start Securing
Free, no credit card | First findings in minutes