CVE-2024-54148

HIGH EPSS 53.2%
Published Dec 23, 20241y ago · Modified Jun 17, 20261w ago
8.7 CVSS 4.0
High
Find Similar
Published Dec 23, 2024 1y ago
Last Modified Jun 17, 2026 1w ago

Description

Gogs is an open source self-hosted Git service. A malicious user is able to commit and edit a crafted symlink file to a repository to gain SSH access to the server. The vulnerability is fixed in 0.13.1.

CVSS Details

Base Score
8.7
Exploitability
Impact
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Attack Vector Network
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope X

Threat Intelligence

EPSS Exploit Probability
53.2% percentile
Exploit & Patch Status
Public Exploit Known
Patch Available

Weaknesses 2

CWE-22 Path Traversal Resource Mgmt
CWE-61

Affected Products 1

VendorProductVersionRange
gogsgogs* <0.13.1

References 4

  • github.com https://github.com/gogs/gogs/commit/c94baec9ca923f38c19f0c7c5af722b9ec04022a
    Patch
  • github.com https://github.com/gogs/gogs/issues/7582
    Issue Tracking
  • github.com https://github.com/gogs/gogs/pull/7857
    Patch
  • github.com https://github.com/gogs/gogs/security/advisories/GHSA-r7j8-5h9c-f6fx
    ExploitVendor Advisory

Remediation

  • github.com https://github.com/gogs/gogs/commit/c94baec9ca923f38c19f0c7c5af722b9ec04022a
    Patch
  • github.com https://github.com/gogs/gogs/pull/7857
    Patch