CVE-2024-55947 is a critical arbitrary file write vulnerability affecting Gogs, an open-source self-hosted Git service. A malicious authenticated user can exploit this flaw to write files to arbitrary server paths, leading to SSH access and full system compromise. With a CVSS score of 8.8 (HIGH) and an EPSS score indicating high exploitability, this vulnerability poses a significant risk due to its low attack complexity and severe impact on confidentiality, integrity, and availability. This zero-day vulnerability is actively exploited in the wild, with multiple media outlets reporting its use to compromise hundreds of servers, despite the absence of public exploit code or a patch at the time of initial exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.13.1CPE matchmatch criteria | cpe:2.3:a:gogs:gogs:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.