PT-2023-9258 · Gogs · Gogs
Published
2023-04-20
·
Updated
2026-05-29
·
CVE-2024-39932
CVSS v3.1
9.9
Critical
| Vector | AC:L/AV:N/A:H/C:H/I:H/PR:L/S:C/UI:N |
Name of the Vulnerable Software and Affected Versions
Gogs versions through 0.13.0
Description
The issue is related to argument injection during the previewing of changes, which can allow a remote attacker to execute arbitrary commands. Unprivileged user accounts can write to arbitrary files on the filesystem, potentially forcing a re-installation of the instance and granting administrator rights. This allows accessing and altering any user's code hosted on the same instance.
Recommendations
For Gogs versions through 0.13.0, upgrade to 0.13.1 or the latest 0.14.0+dev to resolve the issue. As a temporary measure, only grant access to trusted users to your Gogs instance on affected versions.
Exploit
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gogs