¡¾·ì϶¹«¸æ¡¿Gogs ·ûºÅÁ´½ÓÈÆ¹ý·ì϶µ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐ(CVE-2025-8110)

°ä²¼¹¦·ò 2025-12-11

Ò»¡¢·ì϶¸ÅÊö


·ìϼûû³Æ

Gogs ·ûºÅÁ´½ÓÈÆ¹ý·ì϶µ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐ

CVE ID

CVE-2025-8110

·ì϶ÀàÐÍ

RCE

·¢ÏÖ¹¦·ò

2025-12-11

·ì϶ÆÀ·Ö

8.7

·ì϶µÈ¼¶

¸ßΣ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

µÍ

ÀûÓÃÄѶÈ

µÍ

Óû§½»»¥

²»±ØÒª

PoC/EXP

Òѹ«¿ª

ÔÚÒ°ÀûÓÃ

ÒÑ·¢ÏÖ


GogsÊÇÒ»¸öÇáÁ¿¼¶µÄ×ÔÍйÜGit·þÎñ£¬ £¬£¬£¬ £¬£¬£¬Ñ¡È¡Go˵»°¿ª·¢£¬ £¬£¬£¬ £¬£¬£¬ÌṩÀàËÆGitHubµÄÖ°ÄÜ£¬ £¬£¬£¬ £¬£¬£¬Ö§³ÖGit²Ö¿âÖÎÀí¡¢È¨ÏÞ½ÚÔì¡¢´úÂëä¯ÀÀµÈ¡£¡£¡£¡£¡£ËüÒÔÒ×ÓÚ²¿ÊðºÍµÍ×ÊÔ´¿÷ËðÖø³Æ£¬ £¬£¬£¬ £¬£¬£¬ºÏÓÃÓÚÓ×ÎÒºÍÍŶӴ˽ÓÐGit·þÎñ¡£¡£¡£¡£¡£GogsÖ§³ÖWeb½çÃæºÍAPI²Ù×÷£¬ £¬£¬£¬ £¬£¬£¬ÓµÓÐÓÅÁ¼µÄ¿ÉÀ©´óÐÔ£¬ £¬£¬£¬ £¬£¬£¬ÊʺÏÔÚ±¾µØ·þÎñÆ÷»òÔÆ»·¾³ÖÐʹÓᣡ£¡£¡£¡£ÓÉÓÚÆä¿ªÔ´ÇÒ¸ßЧ£¬ £¬£¬£¬ £¬£¬£¬GogsÔÚ¿ª·¢ÕßÖйãÊÜ»¶Ó­£¬ £¬£¬£¬ £¬£¬£¬³ÉΪGit½â¾ö¹æ»®µÄÈȵãÑ¡Ôñ¡£¡£¡£¡£¡£


2025Äê12ÔÂ11ÈÕ£¬ £¬£¬£¬ £¬£¬£¬8827Ì«Ñô¼¯Íż¯ÍÅVSRC¼à²âµ½Gogs·ûºÅÁ´½ÓÈÆ¹ý·ì϶µ¼ÖÂÔ¶³Ì´úÂëÖ´Ðзì϶£¬ £¬£¬£¬ £¬£¬£¬¸Ã·ì϶ÀûÓÃÁËGogs¶Ô·ûºÅÁ´½Ó´¦ÖõIJ»µ±£¬ £¬£¬£¬ £¬£¬£¬¹¥»÷Õß¿ÉÄÜÔÚGit²Ö¿âÖд´½¨Ö¸Ïò±í²¿Ãô¸ÐÎļþµÄ·ûºÅÁ´½Ó£¬ £¬£¬£¬ £¬£¬£¬²¢Í¨¹ýGogs APIµÄPutContents½Ó¿Ú½«Êý¾ÝдÈëÕâЩÎļþ¡£¡£¡£¡£¡£ÓÉÓÚGogsδÄÜÑéÖ¤·ûºÅÁ´½ÓÖ¸±êõè¾¶£¬ £¬£¬£¬ £¬£¬£¬¹¥»÷ÕßÄܹ»¸²¸Ç³ÁҪϵͳÎļþ£¨Èç.git/config£©£¬ £¬£¬£¬ £¬£¬£¬´Ó¶øÖ´ÐжñÒâºÅÁî¡£¡£¡£¡£¡£


¶þ¡¢Ó°ÏìÁìÓò


Gogs <= 0.13.3


Èý¡¢°²È«´ëÊ©


3.1 Éý¼¶°æ±¾


½ûÓÃÊ¢¿ª×¢²á£ºÈôÊDz»±ØÒªÊ¢¿ª×¢²áÖ°ÄÜ£¬ £¬£¬£¬ £¬£¬£¬Á¢¼´½ûÓôËÖ°ÄÜ£¬ £¬£¬£¬ £¬£¬£¬Ô¤·Àδ¾­ÊÚȨµÄÓû§´´½¨²Ö¿â¡£¡£¡£¡£¡£

ÏÞ¶ÈÍøÂç¶³ö£º½«GogsÊ·ý¸éÖÃÓÚÄÚÍø»·¾³£¬ £¬£¬£¬ £¬£¬£¬»òͨ¹ýVPNºÍIP°×Ãûµ¥ÏÞ¶È±í²¿½Ó¼û£¬ £¬£¬£¬ £¬£¬£¬Ï÷¼õ¶³ö·çÏÕ¡£¡£¡£¡£¡£
Éý¼¶Gogs°æ±¾£º¹Ø×¢Gogs¹Ù·½°ä²¼µÄ°²È«²¹¶¡£¬ £¬£¬£¬ £¬£¬£¬ÊµÊ±Éý¼¶µ½½¨¸´°æ±¾¡£¡£¡£¡£¡£


3.2 һʱ´ëÊ©


ÔÝÎÞ¡£¡£¡£¡£¡£


3.3 ͨÓý¨Òé


? ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬ £¬£¬£¬ £¬£¬£¬Ï÷¼õϵͳ·ì϶£¬ £¬£¬£¬ £¬£¬£¬ÌáÉý·þÎñÆ÷µÄ°²È«ÐÔ¡£¡£¡£¡£¡£

¼ÓǿϵͳºÍÍøÂçµÄ½Ó¼û½ÚÔ죬 £¬£¬£¬ £¬£¬£¬Åú¸Ä·À»ðǽսÊõ£¬ £¬£¬£¬ £¬£¬£¬¹Ø¹Ø·Ç±ØÒªµÄÀûÓö˿ڻò·þÎñ£¬ £¬£¬£¬ £¬£¬£¬Ï÷¼õ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Â¶³öµ½¹«Íø£¬ £¬£¬£¬ £¬£¬£¬Ï÷¼õ¹¥»÷Ãæ¡£¡£¡£¡£¡£
ʹÓÃÆóÒµ¼¶°²È«²úÆ·£¬ £¬£¬£¬ £¬£¬£¬ÌáÉýÆóÒµµÄÍøÂ簲ȫ»úÄÜ¡£¡£¡£¡£¡£
¼ÓǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ £¬£¬£¬ £¬£¬£¬ÆôÓöà³É·ÖÈÏÖ¤»úÔìºÍ×îÓ×ȨÏÞ×¼Ôò£¬ £¬£¬£¬ £¬£¬£¬Óû§ºÍÈí¼þȨÏÞӦά³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£¡£
ÆôÓÃÇ¿ÃÜÂëÕ½Êõ²¢ÉèÖÃΪ¶¨ÆÚÅú¸Ä¡£¡£¡£¡£¡£


3.4 ²Î¿¼Á´½Ó


https://nvd.nist.gov/vuln/detail/CVE-2025-8110/
https://www.wiz.io/blog/wiz-research-gogs-cve-2025-8110-rce-exploit