
We found results for “”
CVE-2024-54148
Good to know:

Date: December 23, 2024
Gogs is an open source self-hosted Git service. A malicious user is able to commit and edit a crafted symlink file to a repository to gain SSH access to the server. The vulnerability is fixed in 0.13.1. The original fix version, 0.13.1, was pulled back due to certain issues. The vendor recommends upgrading to 0.13.2. See https://github.com/gogs/gogs/releases/tag/v0.13.1
Severity Score
Related Resources (7)
Severity Score
Weakness Type (CWE)
Top Fix

CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | NONE |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | HIGH |
Integrity (I): | HIGH |
Availability (A): | HIGH |