¡¾·ì϶¹«¸æ¡¿Gogs ·ûºÅÁ´½ÓÈÆ¹ý·ì϶µ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐ(CVE-2025-8110)

°ä²¼¹¦·ò 2025-12-11

Ò»¡¢·ì϶¸ÅÊö


·ìϼûû³Æ

Gogs ·ûºÅÁ´½ÓÈÆ¹ý·ì϶µ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐ

CVE ID

CVE-2025-8110

·ì϶ÀàÐÍ

RCE

·¢ÏÖ¹¦·ò

2025-12-11

·ì϶ÆÀ·Ö

8.7

·ì϶µÈ¼¶

¸ßΣ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

µÍ

ÀûÓÃÄѶÈ

µÍ

Óû§½»»¥

²»±ØÒª

PoC/EXP

Òѹ«¿ª

ÔÚÒ°ÀûÓÃ

ÒÑ·¢ÏÖ


GogsÊÇÒ»¸öÇáÁ¿¼¶µÄ×ÔÍйÜGit·þÎñ£¬Ñ¡È¡Go˵»°¿ª·¢£¬ÌṩÀàËÆGitHubµÄÖ°ÄÜ£¬Ö§³ÖGit²Ö¿âÖÎÀí¡¢È¨ÏÞ½ÚÔì¡¢´úÂëä¯ÀÀµÈ¡£ËüÒÔÒ×ÓÚ²¿ÊðºÍµÍ×ÊÔ´¿÷ËðÖø³Æ£¬ºÏÓÃÓÚÓ×ÎÒºÍÍŶӴ˽ÓÐGit·þÎñ¡£GogsÖ§³ÖWeb½çÃæºÍAPI²Ù×÷£¬ÓµÓÐÓÅÁ¼µÄ¿ÉÀ©´óÐÔ£¬ÊʺÏÔÚ±¾µØ·þÎñÆ÷»òÔÆ»·¾³ÖÐʹÓá£ÓÉÓÚÆä¿ªÔ´ÇÒ¸ßЧ£¬GogsÔÚ¿ª·¢ÕßÖйãÊÜÓ­½Ó£¬³ÉΪGit½â¾ö¹æ»®µÄÈȵãÑ¡Ôñ¡£


2025Äê12ÔÂ11ÈÕ£¬GA»Æ½ð¼×¼¯ÍÅVSRC¼à²âµ½Gogs·ûºÅÁ´½ÓÈÆ¹ý·ì϶µ¼ÖÂÔ¶³Ì´úÂëÖ´Ðзì϶£¬¸Ã·ì϶ÀûÓÃÁËGogs¶Ô·ûºÅÁ´½Ó´¦ÖõIJ»µ±£¬¹¥»÷Õß¿ÉÄÜÔÚGit²Ö¿âÖд´½¨Ö¸Ïò±í²¿Ãô¸ÐÎļþµÄ·ûºÅÁ´½Ó£¬²¢Í¨¹ýGogs APIµÄPutContents½Ó¿Ú½«Êý¾ÝдÈëÕâЩÎļþ¡£ÓÉÓÚGogsδÄÜÑéÖ¤·ûºÅÁ´½ÓÖ¸±êõè¾¶£¬¹¥»÷ÕßÄܹ»¸²¸Ç³ÁҪϵͳÎļþ£¨Èç.git/config£©£¬´Ó¶øÖ´ÐжñÒâºÅÁî¡£


¶þ¡¢Ó°ÏìÁìÓò


Gogs <= 0.13.3


Èý¡¢°²È«´ëÊ©


3.1 Éý¼¶°æ±¾


½ûÓÃÊ¢¿ª×¢²á£ºÈôÊDz»±ØÒªÊ¢¿ª×¢²áÖ°ÄÜ£¬µ±¼´½ûÓôËÖ°ÄÜ£¬Ô¤·Àδ¾­ÊÚȨµÄÓû§´´½¨²Ö¿â¡£

ÏÞ¶ÈÍøÂç¶³ö£º½«GogsÊ·ý¸éÖÃÓÚÄÚÍø»·¾³£¬»òͨ¹ýVPNºÍIP°×Ãûµ¥ÏÞ¶È±í²¿½Ó¼û£¬Ï÷¼õ¶³ö·çÏÕ¡£
Éý¼¶Gogs°æ±¾£º¹Ø×¢Gogs¹Ù·½°ä²¼µÄ°²È«²¹¶¡£¬ÊµÊ±Éý¼¶µ½½¨¸´°æ±¾¡£


3.2 һʱ´ëÊ©


ÔÝÎÞ¡£


3.3 ͨÓý¨Òé


? ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬Ï÷¼õϵͳ·ì϶£¬ÌáÉý·þÎñÆ÷µÄ°²È«ÐÔ¡£

¼ÓǿϵͳºÍÍøÂçµÄ½Ó¼û½ÚÔ죬Åú¸Ä·À»ðǽսÊõ£¬¹Ø¹Ø·Ç±ØÒªµÄÀûÓö˿ڻò·þÎñ£¬Ï÷¼õ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Â¶³öµ½¹«Íø£¬Ï÷¼õ¹¥»÷Ãæ¡£
ʹÓÃÆóÒµ¼¶°²È«²úÆ·£¬ÌáÉýÆóÒµµÄÍøÂ簲ȫ»úÄÜ¡£
¼ÓǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ÆôÓöà³É·ÖÈÏÖ¤»úÔìºÍ×îÓ×ȨÏÞ×¼Ôò£¬Óû§ºÍÈí¼þȨÏÞӦά³ÖÔÚ×îµÍÏÞ¶È¡£
ÆôÓÃÇ¿ÃÜÂëÕ½Êõ²¢ÉèÖÃΪ¶¨ÆÚÅú¸Ä¡£


3.4 ²Î¿¼Á´½Ó


https://nvd.nist.gov/vuln/detail/CVE-2025-8110/
https://www.wiz.io/blog/wiz-research-gogs-cve-2025-8110-rce-exploit