Critical Unpatched Flaws Disclosed in Popular Gogs Open-Source Git Service
ID: 0285579d-dd5e-5c22-b29f-2e16718c62ac
STIX ID: report--0285579d-dd5e-5c22-b29f-2e16718c62ac
Feed Name: The Hacker News
SonarSource disclosed four security flaws in the self-hosted Git service Gogs—three critical (CVE-2024-39930, CVE-2024-39931, CVE-2024-39932) and one high (CVE-2024-39933)—that, if exploited by authenticated users, can enable remote command execution, internal file deletion, and arbitrary file reads including source code and secrets. Exploitation requires authentication (and for one issue, specific SSH/environment conditions); Windows and Docker deployments are not vulnerable, but Debian/Ubuntu instances are due to env --split-string support. The report also warns of 'phantom secrets' in SCM systems where removed secrets may still be retrievable via mirrored or cached commit views.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
