MEDIUM 5.3 Go
Insecure Permissions in Gogs
GHSA-4c7m-vv47-7c69 · CVE-2020-14958 · GO-2022-0788
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
In Gogs 0.11.91, MakeEmailPrimary in models/user_mail.go lacks a "not the owner of the email" check.
Ready to move
Start Securing
Free, no credit card | First findings in minutes