HTTP: Gogs GetDiffPreview Argument Injection

This signature detects attempts to exploit a known vulnerability against Gogs. A successful attack can lead to command injection and arbitrary code execution.

Extended Description

Gogs through 0.13.0 allows argument injection during the previewing of changes.

Affected Products

Gogs gogs

Short Name
HTTP:CTS:GOGS-GETDIFF-ARG-INJ
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
Argument CVE-2024-39932 GetDiffPreview Gogs Injection
Release Date
05/28/2025
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3812
False Positive
Unknown
Vendors

Gogs

Found a potential security threat?