{"id":"GHSA-9pp6-wq8c-3w2c","summary":"Gogs allows argument injection during the previewing of changes","details":"### Impact\n\nUnprivileged user accounts can write to arbitrary files on the filesystem. We could demonstrate its exploitation to force a re-installation of the instance, granting administrator rights. It allows accessing and altering any user's code hosted on the same instance.\n\n### Patches\n\nUnintended Git options has been ignored for diff preview (https://github.com/gogs/gogs/pull/7871). Users should upgrade to 0.13.1 or the latest 0.14.0+dev.\n\n### Workarounds\n\nNo viable workaround available, please only grant access to trusted users to your Gogs instance on affected versions.\n\n### References\n\nhttps://www.cve.org/CVERecord?id=CVE-2024-39932\n","aliases":["CVE-2024-39932","GHSA-hf29-9hfh-w63j","GO-2024-2971"],"modified":"2024-12-23T20:57:01.809999Z","published":"2024-12-23T20:38:27Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-94"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2024-12-23T20:38:27Z"},"references":[{"type":"WEB","url":"https://github.com/gogs/gogs/security/advisories/GHSA-9pp6-wq8c-3w2c"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-39932"},{"type":"PACKAGE","url":"https://github.com/gogs/gogs"},{"type":"WEB","url":"https://www.sonarsource.com/blog/securing-developer-tools-unpatched-code-vulnerabilities-in-gogs-1"}],"affected":[{"package":{"name":"gogs.io/gogs","ecosystem":"Go","purl":"pkg:golang/gogs.io/gogs"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.13.1"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 0.13.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/12/GHSA-9pp6-wq8c-3w2c/GHSA-9pp6-wq8c-3w2c.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AC:L/AV:N/A:H/C:H/I:H/PR:L/S:C/UI:N"}]}