CVE-2024-54148

Gogs is an open source self-hosted Git service. A malicious user is able to commit and edit a crafted symlink file to a repository to gain SSH access to the server. The vulnerability is fixed in 0.13.1.
Configurations

Configuration 1 (hide)

cpe:2.3:a:gogs:gogs:*:*:*:*:*:*:*:*

History

10 Apr 2025, 14:48

Type Values Removed Values Added
First Time Gogs gogs
Gogs
CPE cpe:2.3:a:gogs:gogs:*:*:*:*:*:*:*:*
References () https://github.com/gogs/gogs/commit/c94baec9ca923f38c19f0c7c5af722b9ec04022a - () https://github.com/gogs/gogs/commit/c94baec9ca923f38c19f0c7c5af722b9ec04022a - Patch
References () https://github.com/gogs/gogs/issues/7582 - () https://github.com/gogs/gogs/issues/7582 - Issue Tracking
References () https://github.com/gogs/gogs/pull/7857 - () https://github.com/gogs/gogs/pull/7857 - Patch
References () https://github.com/gogs/gogs/security/advisories/GHSA-r7j8-5h9c-f6fx - () https://github.com/gogs/gogs/security/advisories/GHSA-r7j8-5h9c-f6fx - Exploit, Vendor Advisory
Summary
  • (es) Gogs es un servicio Git autohospedado de código abierto. Un usuario malintencionado puede enviar y editar un archivo de enlace simbólico manipulado en un repositorio para obtener acceso SSH al servidor. La vulnerabilidad se solucionó en 0.13.1.

24 Dec 2024, 02:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

23 Dec 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-23 16:15

Updated : 2025-04-10 14:48


NVD link : CVE-2024-54148

Mitre link : CVE-2024-54148

CVE.ORG link : CVE-2024-54148


JSON object : View

Products Affected

gogs

  • gogs
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CWE-61

UNIX Symbolic Link (Symlink) Following