PT-2023-9258 · Gogs · Gogs

Published

2023-04-20

·

Updated

2026-05-29

·

CVE-2024-39932

CVSS v3.1

9.9

Critical

VectorAC:L/AV:N/A:H/C:H/I:H/PR:L/S:C/UI:N
Name of the Vulnerable Software and Affected Versions Gogs versions through 0.13.0
Description The issue is related to argument injection during the previewing of changes, which can allow a remote attacker to execute arbitrary commands. Unprivileged user accounts can write to arbitrary files on the filesystem, potentially forcing a re-installation of the instance and granting administrator rights. This allows accessing and altering any user's code hosted on the same instance.
Recommendations For Gogs versions through 0.13.0, upgrade to 0.13.1 or the latest 0.14.0+dev to resolve the issue. As a temporary measure, only grant access to trusted users to your Gogs instance on affected versions.

Exploit

Fix

Code Injection

Weakness Enumeration

Related Identifiers

BDU:2024-05767
CVE-2024-39932
GHSA-9PP6-WQ8C-3W2C
GHSA-HF29-9HFH-W63J
GO-2024-2971

Affected Products

Gogs