Back

CRITICAL

Remote Command Execution in gogs/gogs

Published Nov 15, 2024

Description

A remote command execution vulnerability exists in gogs/gogs versions <=0.12.7 when deployed on a Windows server. The vulnerability arises due to improper validation of the `tree_path` parameter during file uploads. An attacker can set `tree_path=.git.` to upload a file into the .git directory, allowing them to write or rewrite the `.git/config` file. If the `core.sshCommand` is set, this can lead to remote command execution.

Affected products

Remediation

No remediation recorded yet.

References (10)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner @huntr_ai
Published Nov 15, 2024
Updated Nov 15, 2024
Reserved May 25, 2022

CISA Vulnrichment

Updated Nov 15, 2024

NVD

Status Analyzed
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner @huntr_ai
Published Nov 15, 2024
Updated Nov 15, 2024