Gitea before 1.11.2 is affected by Trusting HTTP Permission Methods on the Server Side when referencing the vulnerable admin or user API. which could let a remote malisious user execute arbitrary code.
References
Link | Resource |
---|---|
https://github.com/go-gitea/gitea/pull/10465 | Patch Third Party Advisory |
https://blog.gitea.io/2020/03/gitea-1.11.2-is-released/ | Release Notes Vendor Advisory |
https://github.com/go-gitea/gitea/pull/10582 | Patch Third Party Advisory |
https://github.com/go-gitea/gitea/pull/10462 | Patch Third Party Advisory |
Configurations
Information
Published : 2022-02-08 07:15
Updated : 2022-02-11 09:00
NVD link : CVE-2021-45327
Mitre link : CVE-2021-45327
JSON object : View
CWE
Products Affected
gitea
- gitea