← back
CVE-2024-56731criticalCWE-552

Gogs deletion of internal files allows remote command execution

28Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 10epss 0.9%
exploitation probability
0.9%top 42% of all CVEs
observed exploitation
nono source reports it
In short

Gogs allows unprivileged users to delete critical internal Git files and run arbitrary commands on the server. An attacker can take control of the Gogs instance and access or modify any code stored there.

Technical detail

CWE-552 (Files or Directories Accessible to External Parties) allows unauthenticated or low-privilege users to delete files in the .git directory through an incomplete patch, enabling arbitrary command execution with RUN_USER privileges. The vulnerability affects Gogs versions prior to 0.13.3 and can be exploited to compromise all repositories on the instance.

Summary generated and translated by AI from the official description.
Gogs is an open source self-hosted Git service. Prior to version 0.13.3, it's still possible to delete files under the .git directory and achieve remote command execution due to an insufficient patch for CVE-2024-39931. Unprivileged user accounts can execute arbitrary commands on the Gogs instance with the privileges of the account specified by RUN_USER in the configuration. Allowing attackers to access and alter any users' code hosted on the same instance. This issue has been patched in version 0.13.3.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected products
gogs · gogs