Junglewise Threat Intelligence

CVE-2024-39933: GO-2024-2972 - Gogs allows argument injection during the tagging of a new release in github.com/gogs/gogs

CVE-2024-39933 · Severity: low · CVSS 3.1 · Published 2024-07-09

Technologies: github.com/gogs/gogs (Go), gogs.io/gogs (Go). Vendors: Go.

Executive brief

Gogs allows argument injection during the tagging of a new release in github.com/gogs/gogs

Affected products

  • Go github.com/gogs/gogs
  • Go gogs.io/gogs

Related threats