VYPR
High severity8.6NVD Advisory· Published Aug 8, 2018· Updated Jun 17, 2026

CVE-2018-15192

CVE-2018-15192

Description

An SSRF vulnerability in webhooks in Gitea through 1.5.0-rc2 and Gogs through 0.11.53 allows remote attackers to access intranet services.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
code.gitea.io/giteaGo
< 1.16.0-rc11.16.0-rc1
gogs.io/gogsGo
< 0.12.00.12.0

Affected products

6
  • Go Gitea/Gitea3 versions
    cpe:2.3:a:gitea:gitea:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:gitea:gitea:*:*:*:*:*:*:*:*range: <1.5.0
    • cpe:2.3:a:gitea:gitea:1.5.0:rc1:*:*:*:*:*:*
    • cpe:2.3:a:gitea:gitea:1.5.0:rc2:*:*:*:*:*:*
  • cpe:2.3:a:gogs:gogs:*:*:*:*:*:*:*:*
    Range: <=0.11.53
  • ghsa-coords2 versions
    < 1.16.0-rc1+ 1 more
    • (no CPE)range: < 1.16.0-rc1
    • (no CPE)range: < 0.12.0

Patches

Vulnerability mechanics

References

8

News mentions

0

No linked articles in our index yet.