مباشر الأحد، 2 أغسطس 2026
عاجل
سياسةالصحة: الخط الساخن الموحد 105 يسجل أكثر من 38 ألف مكالمة في النصف الأول من العامسياسةهل تؤثر الموجة الحارة على إنتاج اللبن والبيض؟.. الزراعة توضحمنوعاتنسّقي بأسلوب كيت ميدلتون الأخير التنورة الطويلة المكسرة مع البليزرسياسةالتقديم في مدارس المتفوقين stem .. الموعد والضوابط والفئات المسموح بقبولهاعلوم وتكنولوجياالتفاعل مع الفيديوهات مباشرةً.. تعرف على مميزات تحديث ChatGPT الجديدسياسةمحافظ أسيوط يتفقد 15 سيارة تاكسي حديثة تمهيدا لترخيصها وبدء تشغيلهااقتصادأسعار الخضروات والفاكهة اليوم الأحد 2 أغسطس 2026سياسةمصرع شاب في انقلاب دراجة نارية بطريق الحليلة بالأقصرالعالمالحكومة الأرمينية تقدم استقالتها في أول أيام انعقاد البرلمان الجديد – باشينيانعلوم وتكنولوجياالإرث المنسي لنوربرت فينر: هل تأسس الذكاء الاصطناعي الحديث من علم السيبرانية؟ (3/3)منوعاتالأناقة الهادئة تصل إلى الأظافر .. لماذا اختارت أشهر دور الأزياء المناكير الطبيعي؟سياسةشاشة OLED مسطحة بسطوع 6500 شمعة.. تعرف على مواصفات Honor Play 11 Proسياسةإيران تقول إن أمريكا تنقل معدات عسكرية بسفن تجارية عبر هرمزمنوعاتحالة الطقس اليوم.. «الأرصاد» تحذر من ذروة الموجة الحارة والمحسوسة تصل لـ 46 درجةمنوعاتبديل المالديف في أغسطس.. اكتشف سحر جزر الأزور الخفيةمنوعاتاستغرقت 7 ساعات.. كواليس إجراء جامعة سوهاج جراحة خطيرة لطفل أصيب بشلل في الضفيرة العصبيةسياسةمصاريف مدارس ستيم للمتفوقين 2027 .. ماذا أعلنت التعليم؟منوعاتبنك ناصر يواصل دعم مبادرة «وظيفة تك» لتأهيل الشباب وربطهم بسوق العملالعالم“أي مسار يطيل أمد الوضع القائم غير مقبول”: ترامب يجدد اعتراف واشنطن بسيادة المغرب على الصحراء الغربيةسياسةحماية للنيل والمجاري المائية.. 7 أفعال يحظرها قانون الموارد المائيةسياسةالصحة: الخط الساخن الموحد 105 يسجل أكثر من 38 ألف مكالمة في النصف الأول من العامسياسةهل تؤثر الموجة الحارة على إنتاج اللبن والبيض؟.. الزراعة توضحمنوعاتنسّقي بأسلوب كيت ميدلتون الأخير التنورة الطويلة المكسرة مع البليزرسياسةالتقديم في مدارس المتفوقين stem .. الموعد والضوابط والفئات المسموح بقبولهاعلوم وتكنولوجياالتفاعل مع الفيديوهات مباشرةً.. تعرف على مميزات تحديث ChatGPT الجديدسياسةمحافظ أسيوط يتفقد 15 سيارة تاكسي حديثة تمهيدا لترخيصها وبدء تشغيلهااقتصادأسعار الخضروات والفاكهة اليوم الأحد 2 أغسطس 2026سياسةمصرع شاب في انقلاب دراجة نارية بطريق الحليلة بالأقصرالعالمالحكومة الأرمينية تقدم استقالتها في أول أيام انعقاد البرلمان الجديد – باشينيانعلوم وتكنولوجياالإرث المنسي لنوربرت فينر: هل تأسس الذكاء الاصطناعي الحديث من علم السيبرانية؟ (3/3)منوعاتالأناقة الهادئة تصل إلى الأظافر .. لماذا اختارت أشهر دور الأزياء المناكير الطبيعي؟سياسةشاشة OLED مسطحة بسطوع 6500 شمعة.. تعرف على مواصفات Honor Play 11 Proسياسةإيران تقول إن أمريكا تنقل معدات عسكرية بسفن تجارية عبر هرمزمنوعاتحالة الطقس اليوم.. «الأرصاد» تحذر من ذروة الموجة الحارة والمحسوسة تصل لـ 46 درجةمنوعاتبديل المالديف في أغسطس.. اكتشف سحر جزر الأزور الخفيةمنوعاتاستغرقت 7 ساعات.. كواليس إجراء جامعة سوهاج جراحة خطيرة لطفل أصيب بشلل في الضفيرة العصبيةسياسةمصاريف مدارس ستيم للمتفوقين 2027 .. ماذا أعلنت التعليم؟منوعاتبنك ناصر يواصل دعم مبادرة «وظيفة تك» لتأهيل الشباب وربطهم بسوق العملالعالم“أي مسار يطيل أمد الوضع القائم غير مقبول”: ترامب يجدد اعتراف واشنطن بسيادة المغرب على الصحراء الغربيةسياسةحماية للنيل والمجاري المائية.. 7 أفعال يحظرها قانون الموارد المائية
أسعار
دولار أمريكي51.12EGPيورو58.86EGPجنيه إسترليني68.81EGPريال سعودي13.63EGPدرهم إماراتي13.92EGPدينار كويتي165.21EGPدينار أردني72.11EGPريال قطري14.04EGPليرة تركية1.08EGPيوان صيني7.55EGPذهب 246,646.42EGP/جمذهب 215,815.62EGP/جمذهب 184,984.82EGP/جمفضة94.82EGP/جم
دولار أمريكي51.12EGPيورو58.86EGPجنيه إسترليني68.81EGPريال سعودي13.63EGPدرهم إماراتي13.92EGPدينار كويتي165.21EGPدينار أردني72.11EGPريال قطري14.04EGPليرة تركية1.08EGPيوان صيني7.55EGPذهب 246,646.42EGP/جمذهب 215,815.62EGP/جمذهب 184,984.82EGP/جمفضة94.82EGP/جم
خبر عاجل

No fix yet for critical RCE bug in open-source Git service Gogs – exploit module is out

There’s a huge hole and no one is patching it thus far. A critical, remote code execution (RCE) bug in Gogs, a popular open-source self-hosted Git service, can be exploited by any authenticated user – no special privileges required – on a default installation to fully compromise vulnerable servers, steal credentials and multi-factor authentication secrets, or even modify code in hosted repositories in a wide-reaching supply-chain attack. A security researcher reported the 9.4-rated flaw to project maintainers in mid-March. It still doesn’t have a patch. It does, however, have a public Metasploit module – so we’d expect reports of in-the-wild exploitation to start very soon. The vulnerability affects all supported platforms, including Windows, Linux, and macOS, and installation methods, according to Rapid7 researcher Jonah Burgess, who found and reported the bug to Gogs maintainers via GitHub (GHSA-qf6p-p7ww-cwr9) on March 17. After they initially acknowledged that they received the report on March 28, Burgess says he never heard back from the Gogs team – not when he asked them for a status update, nor when he reminded them of the vulnerability disclosure date and asked if they wanted an extension to fix the flaw before its release. “We have not received any further communication from Gogs, and the GHSA has remained unanswered since March 28,” Burgess told The Register. “Because there is currently no official patch, our team submitted a pull request with a suggested fix today [Friday], which is currently awaiting review. At this time, we have no evidence suggesting that this vulnerability is being exploited in the wild.” Gogs sponsor DigitalOcean also did not respond to The Register’s inquiries, including when the security issue would receive a patch. The vulnerability stems from an argument injection flaw in Gogs’ pull request merge flow, specifically the Merge() function in internal/database/pull.go. If a Gogs repo owner or admin enables “Rebase before merging” and a user opens a pull request, the PR’s base branch name gets passed directly to a git rebase command without a — separator to mark the end of command options. Gogs also fails to properly sanitize the input. This means an attacker can create a malicious branch (such as –exec=touch${IFS}/tmp/rce_proof), and Git treats it as an –exec flag, not a branch name, and executes the payload. For Windows installations, the payload delivery method is slightly different, and Burgess developed an exploit module to auto-implement a cross-platform approach. Until the maintainers fix the flaw, Burgess suggests Gogs’ users take the following precautions to mitigate the issue. First, and most importantly, restrict user registration (DISABLE_REGISTRATION = true in app.ini) to prevent untrusted users from creating accounts. Restricting repository creation (MAX_CREATION_LIMIT = 0 in app.ini) to prevent users from creating their own repos also blocks the easiest attack path – creating a new repo with rebase enabled – but it won’t prevent exploitation by users with write access to existing repositories. Finally, audit rebase merge settings, and disable “Rebase before merging” under Settings > Advanced. “Note that this is not an effective defense against a malicious user who owns or has admin access to a repo, since they can re-enable rebase at will,” the threat hunter warns. “There is no global or organization-level setting to restrict this.” ®

المصدر: The Register

0 مشاهدة

أضف تعليقاً

لن يتم نشر عنوان بريدك الإلكتروني. الحقول الإلزامية مشار إليها بـ *