Server Side Request Forgery (SSRF) vulneraility exists in Gitea before 1.7.0 using the OpenID URL.
References
Link | Resource |
---|---|
https://blog.gitea.io/2019/01/gitea-1.7.0-is-released/ | Release Notes Vendor Advisory |
https://github.com/go-gitea/gitea/pull/5705 | Patch Third Party Advisory |
Configurations
Information
Published : 2022-02-08 07:15
Updated : 2022-02-11 09:07
NVD link : CVE-2021-45325
Mitre link : CVE-2021-45325
JSON object : View
CWE
CWE-918
Server-Side Request Forgery (SSRF)
Products Affected
gitea
- gitea