CVE-2024-54148: Gogs has a Path Traversal in file editing UI

8.7 CVSS

Description

Gogs is an open source self-hosted Git service. A malicious user is able to commit and edit a crafted symlink file to a repository to gain SSH access to the server. The vulnerability is fixed in 0.13.1.

Classification

CVE ID: CVE-2024-54148

CVSS Base Severity: HIGH

CVSS Base Score: 8.7

Affected Products

Vendor: gogs

Product: gogs

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.05% (probability of being exploited)

EPSS Percentile: 17.83% (scored less or equal to compared to others)

EPSS Date: 2025-02-04 (when was this score calculated)

References

https://github.com/gogs/gogs/security/advisories/GHSA-r7j8-5h9c-f6fx
https://github.com/gogs/gogs/issues/7582
https://github.com/gogs/gogs/pull/7857
https://github.com/gogs/gogs/commit/c94baec9ca923f38c19f0c7c5af722b9ec04022a

Timeline