No fix yet for critical RCE bug in open-source Git service Gogs - exploit module is out (www.theregister.com)
from cm0002@lemdro.id to cybersecurity@infosec.pub on 30 May 22:32
https://lemdro.id/post/40984027

#cybersecurity

threaded - newest

Arghblarg@lemmy.ca on 31 May 04:29 collapse

Worrisome. My instance thankfully had user self-registration already disabled. Given how aggressive AI-bot repo scrapers have gotten over the past year and a half, I might just shut it down entirely.