Four unpatched vulnerabilities, three of which are critical, have been disclosed in the self-hosted open source Git service Gogs

These vulnerabilities could allow an authorized hacker to compromise sensitive data, intercept or delete source code, and even install backdoors.
According to SonarSource researchers Thomas Chauchefoin and Paul Gerste, the vulnerabilities are as follows:
CVE-2024-39930 (CVSS score: 9.9) – Argument injection in the built-in SSH server
CVE-2024-39931 (CVSS score: 9.9) – Internal file deletion
CVE-2024-39932 (CVSS score: 9.9) – Argument injection when previewing changes
CVE-2024-39933 (CVSS score: 7.7) – Argument injection when tagging new releases
See more: New Zergeca botnet carries out DDoS attacks
Successful exploitation of the first three vulnerabilities could allow a hacker to execute arbitrary commands on the Gogs server. In addition, the fourth flaw allows attackers to read arbitrary files, such as source code and configuration secrets.
In other words, by abusing the issues, a threat actor could read the source code in its current state, modify any code, delete all code, target internal servers accessible from the Gogs server, impersonate other users, and gain additional privileges.
That said, all vulnerabilities require the attacker to have authentication. Specifically, exploiting CVE-2024-39930 requires the threat actor to enable the built-in SSH server, use a specific version of the env binary, and possess a valid SSH private key.

“If registration is enabled on Gogs, the hacker can simply create an account and add their SSH key,” the researchers said. “Otherwise, they would need to compromise an existing account or steal a user’s private SSH key.”
Read more: Recent Intel CPUs affected by new Indirector attack
Gogs installations on Windows are not vulnerable, nor is the Docker image. However, installations on Debian and Ubuntu are vulnerable due to the “–split-string” option supported by the env binary.
Source: thehackernews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
