PT-2023-9257 · Gogs · Gogs

Published

2023-04-20

·

Updated

2025-08-29

·

CVE-2024-39931

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Gogs versions 0.13.0 and earlier
Description The issue allows an attacker to delete or modify arbitrary files on a vulnerable Gogs server. This can be exploited by a remote attacker. Unprivileged user accounts can execute arbitrary commands on the Gogs instance with the privileges of the account specified by RUN USER in the configuration, allowing access and alteration of any users' code hosted on the same instance.
Recommendations For Gogs versions 0.13.0 and earlier, upgrade to 0.13.1 or the latest 0.14.0+dev to resolve the issue. As a temporary workaround, consider granting access only to trusted users to your Gogs instance on affected versions.

Fix

Files Accessible to External Parties

Weakness Enumeration

Related Identifiers

BDU:2024-05766
CVE-2024-39931
GHSA-2VGJ-3PVG-XH4W
GHSA-CCQV-43VM-4F3W
GO-2024-2970

Affected Products

Gogs