PT-2023-9826 · Gogs+1 · Gogs+1
Manassehzhou
·
Published
2023-10-27
·
Updated
2025-12-15
·
CVE-2024-54148
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Gogs versions prior to 0.13.1
Description
The issue is related to errors in handling symbolic links in the Gogs self-hosted Git service. A malicious user can commit and edit a crafted symlink file to a repository, allowing them to gain SSH access to the server.
Recommendations
For versions prior to 0.13.1, upgrade to version 0.13.1 or later to protect the server. As a temporary workaround, consider granting access only to trusted users to the Gogs instance on affected versions.
Exploit
Fix
Path traversal
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gogs
Suse