CVE-2024-44625

Name
CVE-2024-44625
Description
Gogs <=0.13.0 is vulnerable to Directory Traversal via the editFilePost function of internal/route/repo/editor.go.
NVD Severity
high
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
https://gogs.io/
https://fysac.github.io/posts/2024/11/unpatched-remote-code-execution-in-gogs/

Match rules

CPE URI Source package Min version Max version
n/a == n/a == n/a
cpe:2.3:a:gogs:gogs:*:*:*:*:*:*:*:* gogs >= 0 <= 0.13.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
gogs 3.20-community 0.13.0-r14 Will Sinatra <wpsinatra@gmail.com> possibly vulnerable