PT-2023-9257 · Gogs · Gogs
CVE-2024-39931
·
Published
2023-04-20
·
Updated
2025-08-29
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Gogs versions 0.13.0 and earlier
Description
The issue allows an attacker to delete or modify arbitrary files on a vulnerable Gogs server. This can be exploited by a remote attacker. Unprivileged user accounts can execute arbitrary commands on the Gogs instance with the privileges of the account specified by
RUN USER in the configuration, allowing access and alteration of any users' code hosted on the same instance.Recommendations
For Gogs versions 0.13.0 and earlier, upgrade to 0.13.1 or the latest 0.14.0+dev to resolve the issue.
As a temporary workaround, consider granting access only to trusted users to your Gogs instance on affected versions.
Exploit
Fix
Files Accessible to External Parties
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gogs