CVE-2024-39933
HIGH
Published 2024-07-04T00:00:00
Actions:
Expert Analysis
Professional remediation guidance
Get tailored security recommendations from our analyst team for CVE-2024-39933. We'll provide specific mitigation strategies based on your environment and risk profile.
CVSS Score
V3.1
7.7
/10
CVSS:3.1/AC:L/AV:N/A:N/C:H/I:N/PR:L/S:C/UI:N
Base Score Metrics
Exploitability: N/A
Impact: N/A
EPSS Score
v2025.03.14
0.001
probability
of exploitation in the wild
There is a 0.1% chance that this vulnerability will be exploited in the wild within the next 30 days.
Updated: 2025-06-25
Exploit Probability
Percentile: 0.247
Higher than 24.7% of all CVEs
Attack Vector Metrics
Impact Metrics
Description
Gogs through 0.13.0 allows argument injection during the tagging of a new release.
Available Exploits
No exploits available for this CVE.
Related News
No news articles found for this CVE.
GitHub Security Advisories
Community-driven vulnerability intelligence from GitHub
Advisory Details
### Impact
Unprivileged user accounts with at least one SSH key can read arbitrary files on the system. For instance, they could leak the configuration files that could contain database credentials (`[database] *`) and `[security] SECRET_KEY`. Attackers could also exfiltrate TLS certificates, other users' repositories, and the Gogs database when the SQLite driver is enabled.
### Patches
Unintended Git options has been ignored for creating tags (https://github.com/gogs/gogs/pull/7872). Users should upgrade to 0.13.1 or the latest 0.14.0+dev.
### Workarounds
No viable workaround available, please only grant access to trusted users to your Gogs instance on affected versions.
### References
https://www.cve.org/CVERecord?id=CVE-2024-39933
Affected Packages
Go
gogs.io/gogs
ECOSYSTEM:
≥0
<0.13.1
CVSS Scoring
CVSS Score
7.5
CVSS Vector
CVSS:3.1/AC:L/AV:N/A:N/C:H/I:N/PR:L/S:C/UI:N
References
PACKAGE
https://github.com/gogs/gogs
Advisory provided by GitHub Security Advisory Database. Published: December 23, 2024, Modified: December 23, 2024
References
Published: 2024-07-04T00:00:00
Last Modified: 2024-08-02T04:33:11.513Z
Copied to clipboard!