{"id":"GHSA-m27m-h5gj-wwmg","summary":"Gogs allows argument Injection when tagging new releases","details":"### Impact\n\nUnprivileged user accounts with at least one SSH key can read arbitrary files on the system. For instance, they could leak the configuration files that could contain database credentials (`[database] *`) and `[security] SECRET_KEY`. Attackers could also exfiltrate TLS certificates, other users' repositories, and the Gogs database when the SQLite driver is enabled.\n\n### Patches\n\nUnintended Git options has been ignored for creating tags (https://github.com/gogs/gogs/pull/7872). Users should upgrade to 0.13.1 or the latest 0.14.0+dev.\n\n### Workarounds\n\nNo viable workaround available, please only grant access to trusted users to your Gogs instance on affected versions.\n\n### References\n\nhttps://www.cve.org/CVERecord?id=CVE-2024-39933\n","aliases":["CVE-2024-39933","GHSA-8mm6-wmpp-mmm3","GO-2024-2972"],"modified":"2024-12-23T20:59:02.615857Z","published":"2024-12-23T20:38:12Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-88"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2024-12-23T20:38:12Z"},"references":[{"type":"WEB","url":"https://github.com/gogs/gogs/security/advisories/GHSA-m27m-h5gj-wwmg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-39933"},{"type":"WEB","url":"https://github.com/gogs/gogs/pull/7872"},{"type":"WEB","url":"https://github.com/gogs/gogs/commit/76831d0d06c44c5cf46dc22b380440b7507c2f07"},{"type":"PACKAGE","url":"https://github.com/gogs/gogs"},{"type":"WEB","url":"https://www.sonarsource.com/blog/securing-developer-tools-unpatched-code-vulnerabilities-in-gogs-1"}],"affected":[{"package":{"name":"gogs.io/gogs","ecosystem":"Go","purl":"pkg:golang/gogs.io/gogs"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.13.1"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 0.13.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/12/GHSA-m27m-h5gj-wwmg/GHSA-m27m-h5gj-wwmg.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AC:L/AV:N/A:N/C:H/I:N/PR:L/S:C/UI:N"}]}