HIGH 8.8 Go

Remote Code Execution in Gogs

GHSA-phm4-wf3h-pc3r · CVE-2024-44625 · GO-2024-3275

Published · Modified

Description

Gogs <0.13.2 is vulnerable to symbolic link path traversal that enables remote code execution via the editFilePost function of internal/route/repo/editor.go.

Ready to move

Start Securing

Free, no credit card | First findings in minutes