CVE-2024-44625: Path Traversal
Published Nov 15, 2024
·Updated
Gogs <=0.13.0 is vulnerable to Directory Traversal via the editFilePost function of internal/route/repo/editor.go.
Affected Software
2 affected components
go/gogs.io/gogs<=0.13.0
Gogs Gogs<=0.13.0
Event History
Nov 15, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Advisory Published
via GitHub·06:30 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-44625?
CVE-2024-44625 is classified as a critical vulnerability due to its potential for directory traversal attacks.
2
How do I fix CVE-2024-44625?
To fix CVE-2024-44625, update Gogs to a version higher than 0.13.0.
3
What software versions are affected by CVE-2024-44625?
CVE-2024-44625 affects Gogs versions up to and including 0.13.0.
4
What type of vulnerability is CVE-2024-44625?
CVE-2024-44625 is a directory traversal vulnerability that allows unauthorized file access.
5
Can CVE-2024-44625 lead to remote code execution?
Yes, CVE-2024-44625 can lead to remote code execution if exploited.