← Back to browse · API

CVE-2024-55947

Severity
HIGH
CVSS
8.7
EPSS
0.75197
Risk score
61.12
CISA KEV
No
PoC
Yes
Published
2024-12-23
Modified
2024-12-24
First seen
2026-08-07
Aliases
EUVD-2024-3608, GHSA-QF5V-RP47-55GG
Products
gogs:gogs < 0.13.1
Sources
packetstorm 3ca3e115f0a00fa6375287f3|CVE-2024-55947
euvd EUVD-2024-3608

Description

Gogs is an open source self-hosted Git service. A malicious user is able to write a file to an arbitrary path on the server to gain SSH access to the server. The vulnerability is fixed in 0.13.1.

References