PT-2023-9259 · Gogs · Gogs

Paul Gerste

+1

·

Published

2023-04-20

·

Updated

2025-04-10

·

CVE-2024-39933

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Gogs versions 0.13.0 and earlier
Description The issue is related to argument injection during the tagging of a new release. This could allow a remote attacker to disclose protected information. Unprivileged user accounts with at least one SSH key can read arbitrary files on the system, potentially leaking configuration files with database credentials, such as [database] and [security] SECRET KEY, as well as exfiltrating TLS certificates, other users' repositories, and the Gogs database when the SQLite driver is enabled.
Recommendations For Gogs versions 0.13.0 and earlier, upgrade to version 0.13.1 or the latest 0.14.0+dev to resolve the issue. As a temporary measure, only grant access to trusted users to your Gogs instance on affected versions, as there is no viable workaround available.

Exploit

Fix

Argument Injection

Weakness Enumeration

Related Identifiers

BDU:2024-05768
CVE-2024-39933
GHSA-8MM6-WMPP-MMM3
GHSA-M27M-H5GJ-WWMG
GO-2024-2972

Affected Products

Gogs