Gogs - Authentication Bypass via Unvalidated Reverse Proxy Headers
Gogs - Authentication Bypass via Unvalidated Reverse Proxy Headers When 'ENABLE_REVERSE_PROXY_AUTHENTICATION' is enabled, Gogs accepts the configured authentication header (default: 'X-WEBAUTH-USER') directly from client requests without validating that the request originated from a trusted reverse…
Sources
- T1Gogs - Authentication Bypass via Unvalidated Reverse Proxy HeadersTenable Research