Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-5qhx-gwfj-6jqr | Gogs user can update repository content with read-only permission |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 06 Feb 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 06 Feb 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, the endpoint "PUT /repos/:owner/:repo/contents/*" does not require write permissions and allows access with read permission only via repoAssignment(). After passing the permission check, PutContents() invokes UpdateRepoFile(), which results in commit creation and the execution of git push. As a result, a token with read-only permission can be used to modify repository contents. This issue has been patched in versions 0.13.4 and 0.14.0+dev. | |
| Title | Gogs user can update repository content with read-only permission | |
| Weaknesses | CWE-862 CWE-863 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-02-06T18:54:15.180Z
Reserved: 2026-01-14T16:08:37.482Z
Link: CVE-2026-23632
Updated: 2026-02-06T18:54:11.066Z
Status : Awaiting Analysis
Published: 2026-02-06T18:15:56.553
Modified: 2026-02-06T21:57:22.450
Link: CVE-2026-23632
No data.
OpenCVE Enrichment
No data.
Github GHSA