blob: f57c513deaaec09065a774cca17ea710c4d96ff0 [file] [log] [blame]
id: GO-2024-2972
modules:
- module: github.com/gogs/gogs
unsupported_versions:
- last_affected: 0.13.0
vulnerable_at: 0.13.0
summary: Gogs allows argument injection during the tagging of a new release in github.com/gogs/gogs
cves:
- CVE-2024-39933
ghsas:
- GHSA-8mm6-wmpp-mmm3
references:
- advisory: https://github.com/advisories/GHSA-8mm6-wmpp-mmm3
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2024-39933
- web: https://www.sonarsource.com/blog/securing-developer-tools-unpatched-code-vulnerabilities-in-gogs-1
source:
id: GHSA-8mm6-wmpp-mmm3
created: 2024-07-08T13:24:01.718651-04:00
review_status: UNREVIEWED