CVE-2024-39930 is a critical argument injection vulnerability affecting the built-in SSH server in Gogs through version 0.13.0, leading to remote code execution. This flaw allows authenticated attackers to execute arbitrary code by sending a specially crafted SSH request, though Windows installations are not impacted. Rated 9.9 CVSS (Critical), it has a low attack complexity and high impact on confidentiality, integrity, and availability. While not yet in CISA KEV, public exploit code is available via ExploitDB, and there is community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.13.0CPE matchmatch criteria | cpe:2.3:a:gogs:gogs:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.