[gogs.io/gogs] OS Command Injection in gogs

Impact
The malicious user is able to update a crafted config file into repository’s .git directory with to gain SSH access to the server. All installations with repository upload enabled (default) are affected.
Patches
Repository file updates are prohi…

[gogs.io/gogs] OS Command Injection in gogs

Impact
The malicious user is able to upload a crafted config file into repository’s .git directory with to gain SSH access to the server. All Windows installations with repository upload enabled (default) are affected.
Patches
Repository file uploads a…

[gogs.io/gogs] OS Command Injection in gogs

Impact
The malicious user is able to upload a crafted config file into repository’s .git directory with to gain SSH access to the server. All Windows installations with repository upload enabled (default) are affected.
Patches
Repository file uploads a…

[ctx] Embedded Malicious Code in ctx

The ctx hosted project on PyPI was taken over via user account compromise and replaced with a malicious project which contained runtime code which collected the content of os.environ.items() when instantiating Ctx objects.
References

https://github.co…