diff --git a/advisories/github-reviewed/2024/07/GHSA-2vgj-3pvg-xh4w/GHSA-2vgj-3pvg-xh4w.json b/advisories/github-reviewed/2024/07/GHSA-2vgj-3pvg-xh4w/GHSA-2vgj-3pvg-xh4w.json index 015aff2b4ef..f8f96d129cf 100644 --- a/advisories/github-reviewed/2024/07/GHSA-2vgj-3pvg-xh4w/GHSA-2vgj-3pvg-xh4w.json +++ b/advisories/github-reviewed/2024/07/GHSA-2vgj-3pvg-xh4w/GHSA-2vgj-3pvg-xh4w.json @@ -1,13 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-2vgj-3pvg-xh4w", - "modified": "2024-07-09T21:41:08Z", + "modified": "2024-12-23T20:37:05Z", "published": "2024-07-04T18:31:10Z", - "aliases": [ - "CVE-2024-39931" - ], - "summary": "Gogs allows deletion of internal files", - "details": "Gogs through 0.13.0 allows deletion of internal files. ", + "withdrawn": "2024-12-23T20:37:05Z", + "aliases": [], + "summary": "Duplicate Advisory: Gogs allows deletion of internal files", + "details": "# Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-ccqv-43vm-4f3w. This link is maintained to preserve external references.\n\n# Original Description\nGogs through 0.13.0 allows deletion of internal files. ", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/github-reviewed/2024/07/GHSA-8mm6-wmpp-mmm3/GHSA-8mm6-wmpp-mmm3.json b/advisories/github-reviewed/2024/07/GHSA-8mm6-wmpp-mmm3/GHSA-8mm6-wmpp-mmm3.json index a26b2d907a3..e76836e8097 100644 --- a/advisories/github-reviewed/2024/07/GHSA-8mm6-wmpp-mmm3/GHSA-8mm6-wmpp-mmm3.json +++ b/advisories/github-reviewed/2024/07/GHSA-8mm6-wmpp-mmm3/GHSA-8mm6-wmpp-mmm3.json @@ -1,13 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-8mm6-wmpp-mmm3", - "modified": "2024-09-06T21:38:52Z", + "modified": "2024-12-23T20:36:51Z", "published": "2024-07-04T18:31:11Z", - "aliases": [ - "CVE-2024-39933" - ], - "summary": "Gogs allows argument injection during the tagging of a new release", - "details": "Gogs through 0.13.0 allows argument injection during the tagging of a new release. This vulnerability is still unfixed as of the time of this advisory being published.", + "withdrawn": "2024-12-23T20:36:50Z", + "aliases": [], + "summary": "Duplicate Advisory: Gogs allows argument injection during the tagging of a new release", + "details": "# Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-m27m-h5gj-wwmg. This link is maintained to preserve external references.\n\n# Original Description\nGogs through 0.13.0 allows argument injection during the tagging of a new release. This vulnerability is still unfixed as of the time of this advisory being published.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/github-reviewed/2024/07/GHSA-hf29-9hfh-w63j/GHSA-hf29-9hfh-w63j.json b/advisories/github-reviewed/2024/07/GHSA-hf29-9hfh-w63j/GHSA-hf29-9hfh-w63j.json index bde1edd1688..7ddd5b863b1 100644 --- a/advisories/github-reviewed/2024/07/GHSA-hf29-9hfh-w63j/GHSA-hf29-9hfh-w63j.json +++ b/advisories/github-reviewed/2024/07/GHSA-hf29-9hfh-w63j/GHSA-hf29-9hfh-w63j.json @@ -1,13 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-hf29-9hfh-w63j", - "modified": "2024-07-09T21:56:17Z", + "modified": "2024-12-23T20:37:17Z", "published": "2024-07-04T18:31:11Z", - "aliases": [ - "CVE-2024-39932" - ], - "summary": "Gogs allows argument injection during the previewing of changes", - "details": "Gogs through 0.13.0 allows argument injection during the previewing of changes.", + "withdrawn": "2024-12-23T20:37:16Z", + "aliases": [], + "summary": "Duplicate Advisory: Gogs allows argument injection during the previewing of changes", + "details": "# Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-9pp6-wq8c-3w2c. This link is maintained to preserve external references.\n\n# Original Description\nGogs through 0.13.0 allows argument injection during the previewing of changes.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/github-reviewed/2024/07/GHSA-p69r-v3h4-rj4f/GHSA-p69r-v3h4-rj4f.json b/advisories/github-reviewed/2024/07/GHSA-p69r-v3h4-rj4f/GHSA-p69r-v3h4-rj4f.json index 69dc1ebff2f..c74cd72b09d 100644 --- a/advisories/github-reviewed/2024/07/GHSA-p69r-v3h4-rj4f/GHSA-p69r-v3h4-rj4f.json +++ b/advisories/github-reviewed/2024/07/GHSA-p69r-v3h4-rj4f/GHSA-p69r-v3h4-rj4f.json @@ -1,13 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-p69r-v3h4-rj4f", - "modified": "2024-08-28T20:13:03Z", + "modified": "2024-12-23T20:37:29Z", "published": "2024-07-04T18:31:10Z", - "aliases": [ - "CVE-2024-39930" - ], - "summary": "github.com/gogs/gogs affected by CVE-2024-39930", - "details": "The built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code execution. Authenticated attackers can exploit this by opening an SSH connection and sending a malicious --split-string env request if the built-in SSH server is activated. Windows installations are unaffected.", + "withdrawn": "2024-12-23T20:37:28Z", + "aliases": [], + "summary": "Duplicate Advisory: github.com/gogs/gogs affected by CVE-2024-39930", + "details": "# Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-vm62-9jw3-c8w3. This link is maintained to preserve external references.\n\n# Original Description\nThe built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code execution. Authenticated attackers can exploit this by opening an SSH connection and sending a malicious --split-string env request if the built-in SSH server is activated. Windows installations are unaffected.", "severity": [ { "type": "CVSS_V3",