logo

Critical Unpatched Flaws Disclosed in Popular Gogs Open-Source Git Service

ID: 0285579d-dd5e-5c22-b29f-2e16718c62ac

STIX ID: report--0285579d-dd5e-5c22-b29f-2e16718c62ac

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-07-08

Date Updated: 2026-05-08

Author: [email protected] (The Hacker News)

...
...

SonarSource disclosed four security flaws in the self-hosted Git service Gogs—three critical (CVE-2024-39930, CVE-2024-39931, CVE-2024-39932) and one high (CVE-2024-39933)—that, if exploited by authenticated users, can enable remote command execution, internal file deletion, and arbitrary file reads including source code and secrets. Exploitation requires authentication (and for one issue, specific SSH/environment conditions); Windows and Docker deployments are not vulnerable, but Debian/Ubuntu instances are due to env --split-string support. The report also warns of 'phantom secrets' in SCM systems where removed secrets may still be retrievable via mirrored or cached commit views.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.