vendor:
Gitea
by:
1F98D
8.8
CVSS
HIGH
Remote Code Execution
20
CWE
Product Name: Gitea
Affected Version From: Gitea before 1.7.6 and 1.8.x before 1.8-RC3
Affected Version To: Gitea 1.7.5
Patch Exists: YES
Related CWE: CVE-2019-11229
CPE: a:gitea_project:gitea:1.7.5
Platforms Tested: Debian 9.11 (x64)
2020
Gitea 1.7.5 – Remote Code Execution
Gitea before 1.7.6 and 1.8.x before 1.8-RC3 mishandles mirror repo URL settings, leading to authenticated remote code execution.
Mitigation:
Upgrade to Gitea version 1.7.6 or later.