CVE-2024-39930
CVSS 3.1 Score 9.9 of 10 (high)
Details
Summary
CVE-2024-39930 is a vulnerability affecting versions of the Gogs self-hosted Git service up to 0.13.0. Hackers can exploit this issue by injecting malicious arguments during SSH sessions, resulting in remote code execution. This occurs in the internal/ssh/ssh.go file of the built-in SSH server. Although the weakness does not affect Windows installations, it poses a significant threat to other systems if the internal SSH server is enabled. Authenticated attackers can initiate this exploit by opening an SSH connection and sending a malicious --split-string env request.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Gogs