HomeSecurityVulnerabilities Revealed in Gogs Open-Source Git Service

Vulnerabilities Revealed in Gogs Open-Source Git Service

Four unpatched vulnerabilities, three of which are critical, have been disclosed in the self-hosted open source Git service Gogs

Gogs

These vulnerabilities could allow an authorized hacker to compromise sensitive data, intercept or delete source code, and even install backdoors.

According to SonarSource researchers Thomas Chauchefoin and Paul Gerste, the vulnerabilities are as follows:

CVE-2024-39930 (CVSS score: 9.9) – Argument injection in the built-in SSH server
CVE-2024-39931 (CVSS score: 9.9) – Internal file deletion
CVE-2024-39932 (CVSS score: 9.9) – Argument injection when previewing changes
CVE-2024-39933 (CVSS score: 7.7) – Argument injection when tagging new releases

See more: New Zergeca botnet carries out DDoS attacks

Successful exploitation of the first three vulnerabilities could allow a hacker to execute arbitrary commands on the Gogs server. In addition, the fourth flaw allows attackers to read arbitrary files, such as source code and configuration secrets.

In other words, by abusing the issues, a threat actor could read the source code in its current state, modify any code, delete all code, target internal servers accessible from the Gogs server, impersonate other users, and gain additional privileges.

That said, all vulnerabilities require the attacker to have authentication. Specifically, exploiting CVE-2024-39930 requires the threat actor to enable the built-in SSH server, use a specific version of the env binary, and possess a valid SSH private key.

Gogs

“If registration is enabled on Gogs, the hacker can simply create an account and add their SSH key,” the researchers said. “Otherwise, they would need to compromise an existing account or steal a user’s private SSH key.”

Read more: Recent Intel CPUs affected by new Indirector attack

Gogs installations on Windows are not vulnerable, nor is the Docker image. However, installations on Debian and Ubuntu are vulnerable due to the “–split-string” option supported by the env binary.

Source: thehackernews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS