{"id":"GHSA-p69r-v3h4-rj4f","summary":"Duplicate Advisory: github.com/gogs/gogs affected by CVE-2024-39930","details":"# Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-vm62-9jw3-c8w3. This link is maintained to preserve external references.\n\n# Original Description\nThe built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code execution. Authenticated attackers can exploit this by opening an SSH connection and sending a malicious --split-string env request if the built-in SSH server is activated. Windows installations are unaffected.","aliases":["CVE-2024-39930","GHSA-vm62-9jw3-c8w3","GO-2024-2969"],"modified":"2024-12-23T20:56:55.885554Z","published":"2024-07-04T18:31:10Z","withdrawn":"2024-12-23T20:37:28Z","database_specific":{"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2024-07-10T14:30:51Z","nvd_published_at":"2024-07-04T16:15:02Z","cwe_ids":["CWE-88"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-39930"},{"type":"PACKAGE","url":"https://github.com/gogs/gogs"},{"type":"WEB","url":"https://github.com/gogs/gogs/releases"},{"type":"WEB","url":"https://www.sonarsource.com/blog/securing-developer-tools-unpatched-code-vulnerabilities-in-gogs-1"},{"type":"WEB","url":"https://www.vicarius.io/vsociety/posts/argument-injection-in-gogs-ssh-server-cve-2024-39930"}],"affected":[{"package":{"name":"github.com/gogs/gogs","ecosystem":"Go","purl":"pkg:golang/github.com/gogs/gogs"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"0.13.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/07/GHSA-p69r-v3h4-rj4f/GHSA-p69r-v3h4-rj4f.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"}]}