CVE Database
/

CVE-2024-54148

Back to search

CVE-2024-54148

Published: Dec 23, 2024

Modified: Dec 24, 2024

PUBLISHED

Description

Gogs is an open source self-hosted Git service. A malicious user is able to commit and edit a crafted symlink file to a repository to gain SSH access to the server. The vulnerability is fixed in 0.13.1.

VendorProductVersions

gogs

gogs

affected
< 0.13.1

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now