CVE-2024-44625
Unpatched Remote Code Execution in Gogs in gogs.io/gogs
Description
Gogs <=0.13.0 is vulnerable to Directory Traversal via the editFilePost function of internal/route/repo/editor.go.
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
gogogs.io/gogs
Metrics
96.9 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
Show all metrics
Severity
none
82.26
PoC (publicly reported)
Published
2024-11-19 17:20 UTC
References & sources
- https://github.com/advisories/GHSA-phm4-wf3h-pc3radvisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-44625advisory
- https://fysac.github.io/posts/2024/11/unpatched-remote-code-execution-in-gogsweb
- https://gogs.io/
- https://fysac.github.io/posts/2024/11/unpatched-remote-code-execution-in-gogs/
- https://github.com/gogs/gogspackage
- https://gogs.ioweb
- https://pkg.go.dev/vuln/GO-2024-3275web