CVE-2024-55947

Gogs is an open source self-hosted Git service. A malicious user is able to write a file to an arbitrary path on the server to gain SSH access to the server. The vulnerability is fixed in 0.13.1.
Configurations

Configuration 1 (hide)

cpe:2.3:a:gogs:gogs:*:*:*:*:*:*:*:*

History

10 Apr 2025, 14:47

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
First Time Gogs gogs
Gogs
References () https://github.com/gogs/gogs/commit/9a9388ace25bd646f5098cb9193d983332c34e41 - () https://github.com/gogs/gogs/commit/9a9388ace25bd646f5098cb9193d983332c34e41 - Patch
References () https://github.com/gogs/gogs/issues/7582 - () https://github.com/gogs/gogs/issues/7582 - Issue Tracking
References () https://github.com/gogs/gogs/pull/7859 - () https://github.com/gogs/gogs/pull/7859 - Patch
References () https://github.com/gogs/gogs/security/advisories/GHSA-qf5v-rp47-55gg - () https://github.com/gogs/gogs/security/advisories/GHSA-qf5v-rp47-55gg - Exploit, Vendor Advisory
CPE cpe:2.3:a:gogs:gogs:*:*:*:*:*:*:*:*

24 Dec 2024, 16:15

Type Values Removed Values Added
References () https://github.com/gogs/gogs/security/advisories/GHSA-qf5v-rp47-55gg - () https://github.com/gogs/gogs/security/advisories/GHSA-qf5v-rp47-55gg -
Summary
  • (es) Gogs es un servicio Git autohospedado de código abierto. Un usuario malintencionado puede escribir un archivo en una ruta arbitraria del servidor para obtener acceso SSH al servidor. La vulnerabilidad se solucionó en 0.13.1.

23 Dec 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-23 16:15

Updated : 2025-04-10 14:47


NVD link : CVE-2024-55947

Mitre link : CVE-2024-55947

CVE.ORG link : CVE-2024-55947


JSON object : View

Products Affected

gogs

  • gogs
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')