Gogs is an open source self-hosted Git service. A malicious user is able to commit and edit a crafted symlink file to a repository to gain SSH access to the server. The vulnerability is fixed in 0.13.1.
References
| Link | Resource |
|---|---|
| https://github.com/gogs/gogs/commit/c94baec9ca923f38c19f0c7c5af722b9ec04022a | Patch |
| https://github.com/gogs/gogs/issues/7582 | Issue Tracking |
| https://github.com/gogs/gogs/pull/7857 | Patch |
| https://github.com/gogs/gogs/security/advisories/GHSA-r7j8-5h9c-f6fx | Exploit Vendor Advisory |
Configurations
History
No history.
Information
Published : 2024-12-23 16:15
Updated : 2025-04-10 14:48
NVD link : CVE-2024-54148
Mitre link : CVE-2024-54148
CVE.ORG link : CVE-2024-54148
JSON object : View
Products Affected
gogs
- gogs
