Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-3608 | Path Traversal in file update API in gogs |
Github GHSA |
GHSA-qf5v-rp47-55gg | Path Traversal in file update API in gogs |
Thu, 10 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gogs
Gogs gogs |
|
| CPEs | cpe:2.3:a:gogs:gogs:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gogs
Gogs gogs |
|
| Metrics |
cvssV3_1
|
Tue, 24 Dec 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 23 Dec 2024 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Gogs is an open source self-hosted Git service. A malicious user is able to write a file to an arbitrary path on the server to gain SSH access to the server. The vulnerability is fixed in 0.13.1. | |
| Title | Gogs has a Path Traversal in file update API | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-12-24T15:59:02.793Z
Reserved: 2024-12-13T17:39:32.960Z
Link: CVE-2024-55947
Updated: 2024-12-24T15:58:56.619Z
Status : Analyzed
Published: 2024-12-23T16:15:07.253
Modified: 2025-04-10T14:47:42.700
Link: CVE-2024-55947
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA