{"id":"GHSA-vm62-9jw3-c8w3","summary":"Gogs has an argument Injection in the built-in SSH server","details":"### Impact\n\nWhen the built-in SSH server is enabled (`[server] START_SSH_SERVER = true`), unprivileged user accounts with at least one SSH key can execute arbitrary commands on the Gogs instance with the privileges of the user specified by `RUN_USER` in the configuration. It allows attackers to access and alter any users' code hosted on the same instance.\n\n### Patches\n\nThe `env` command sent to the internal SSH server has been changed to be a passthrough (https://github.com/gogs/gogs/pull/7868), i.e. the feature is effectively removed. Users should upgrade to 0.13.1 or the latest 0.14.0+dev.\n\n### Workarounds\n\n[Disable the use of built-in SSH server](https://github.com/gogs/gogs/blob/7adac94f1e93cc5c3545ea31688662dcef9cd737/conf/app.ini#L76-L77) on operating systems other than Windows.\n\n### References\n\nhttps://www.cve.org/CVERecord?id=CVE-2024-39930\n","aliases":["CVE-2024-39930","GHSA-p69r-v3h4-rj4f","GO-2024-2969"],"modified":"2024-12-23T20:56:55.885554Z","published":"2024-12-23T20:38:34Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2024-12-23T20:38:34Z","nvd_published_at":null,"cwe_ids":["CWE-88"],"severity":"CRITICAL"},"references":[{"type":"WEB","url":"https://github.com/gogs/gogs/security/advisories/GHSA-vm62-9jw3-c8w3"},{"type":"PACKAGE","url":"https://github.com/gogs/gogs"},{"type":"WEB","url":"https://www.sonarsource.com/blog/securing-developer-tools-unpatched-code-vulnerabilities-in-gogs-1"},{"type":"WEB","url":"https://www.vicarius.io/vsociety/posts/argument-injection-in-gogs-ssh-server-cve-2024-39930"}],"affected":[{"package":{"name":"gogs.io/gogs","ecosystem":"Go","purl":"pkg:golang/gogs.io/gogs"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.13.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/12/GHSA-vm62-9jw3-c8w3/GHSA-vm62-9jw3-c8w3.json","last_known_affected_version_range":"\u003c= 0.13.0"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AC:L/AV:N/A:H/C:H/I:H/PR:L/S:C/UI:N"}]}