CVE-2024-55947: Gogs has a Path Traversal in file update API

8.7 CVSS

Description

Gogs is an open source self-hosted Git service. A malicious user is able to write a file to an arbitrary path on the server to gain SSH access to the server. The vulnerability is fixed in 0.13.1.

Classification

CVE ID: CVE-2024-55947

CVSS Base Severity: HIGH

CVSS Base Score: 8.7

Affected Products

Vendor: gogs

Product: gogs

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.05% (probability of being exploited)

EPSS Percentile: 17.83% (scored less or equal to compared to others)

EPSS Date: 2025-02-04 (when was this score calculated)

References

https://github.com/gogs/gogs/security/advisories/GHSA-qf5v-rp47-55gg
https://github.com/gogs/gogs/issues/7582
https://github.com/gogs/gogs/pull/7859
https://github.com/gogs/gogs/commit/9a9388ace25bd646f5098cb9193d983332c34e41

Timeline