PT-2023-12641 · Gogs · Gogs

Published

2023-02-25

·

Updated

2024-08-20

·

CVE-2022-2024

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions gogs/gogs versions prior to 0.12.11
Description The issue allows a malicious user to update a crafted config file into a repository's .git directory, in combination with crafted file deletion, to gain SSH access to the server on case-insensitive file systems. This affects all installations with repository upload enabled, which is the default setting, on case-insensitive file systems such as Windows and macOS.
Recommendations For versions prior to 0.12.11, upgrade to 0.12.11 or the latest 0.13.0+dev to resolve the issue. As a temporary workaround, consider disabling repository upload to minimize the risk of exploitation.

Exploit

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2022-2024
GHSA-PFVH-P8QP-9WW9
GO-2023-1596

Affected Products

Gogs