{"id":"GHSA-ccqv-43vm-4f3w","summary":"Gogs allows deletion of internal files","details":"### Impact\n\nUnprivileged user accounts can execute arbitrary commands on the Gogs instance with the privileges of the account specified by `RUN_USER` in the configuration. It allows attackers to access and alter any users' code hosted on the same instance.\n\n### Patches\n\nDeletion of `.git` files has been prohibited (https://github.com/gogs/gogs/pull/7870). Users should upgrade to 0.13.1 or the latest 0.14.0+dev.\n\n### Workarounds\n\nNo viable workaround available, please only grant access to trusted users to your Gogs instance on affected versions.\n\n### References\n\nhttps://www.cve.org/CVERecord?id=CVE-2024-39931\n","aliases":["CVE-2024-39931","GHSA-2vgj-3pvg-xh4w","GO-2024-2970"],"modified":"2024-12-23T20:56:58.642991Z","published":"2024-12-23T20:38:20Z","database_specific":{"github_reviewed_at":"2024-12-23T20:38:20Z","nvd_published_at":null,"cwe_ids":["CWE-552"],"severity":"CRITICAL","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/gogs/gogs/security/advisories/GHSA-ccqv-43vm-4f3w"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-39931"},{"type":"PACKAGE","url":"https://github.com/gogs/gogs"},{"type":"WEB","url":"https://www.sonarsource.com/blog/securing-developer-tools-unpatched-code-vulnerabilities-in-gogs-1"}],"affected":[{"package":{"name":"gogs.io/gogs","ecosystem":"Go","purl":"pkg:golang/gogs.io/gogs"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.13.1"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 0.13.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/12/GHSA-ccqv-43vm-4f3w/GHSA-ccqv-43vm-4f3w.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AC:L/AV:N/A:H/C:H/I:H/PR:L/S:C/UI:N"}]}