CVE-2024-39932

Name
CVE-2024-39932
Description
Gogs through 0.13.0 allows argument injection during the previewing of changes.
NVD Severity
high
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
https://github.com/gogs/gogs/releases
https://www.sonarsource.com/blog/securing-developer-tools-unpatched-code-vulnerabilities-in-gogs-1/

Match rules

CPE URI Source package Min version Max version
n/a == n/a == n/a
cpe:2.3:a:gogs:gogs:*:*:*:*:*:*:*:* gogs == 0.13.0 == 0.13.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
gogs edge-community 0.13.0-r14 Will Sinatra <wpsinatra@gmail.com> possibly vulnerable
gogs 3.20-community 0.13.0-r14 Will Sinatra <wpsinatra@gmail.com> possibly vulnerable