Lack of data validation - Path Traversal In gogs.io/gogs
Description
Gogs vulnerable to a bypass of CVE-2024-55947 Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version |
|---|---|---|
go |
Aliases
1. 2. 3. 4. 5.
References
1. 2. 3. 4. 5. 6. 7. 8. 9. 10. 11. 12.