CVE-2024-44625

Unpatched Remote Code Execution in Gogs in gogs.io/gogs

Description

Gogs <=0.13.0 is vulnerable to Directory Traversal via the editFilePost function of internal/route/repo/editor.go.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

gogogs.io/gogs

Metrics

96.9 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
Show all metrics
Severity
none
PoC (publicly reported)
16.5 %
Elevated — model estimates 10-50% exploitation likelihood.
Published
2024-11-19 17:20 UTC

References & sources