7.2

CVE-2020-14144

Exploit
The git hook feature in Gitea 1.1.0 through 1.12.5 might allow for authenticated remote code execution in customer environments where the documentation was not understood (e.g., one viewpoint is that the dangerousness of this feature should be documented immediately above the ENABLE_GIT_HOOKS line in the config file). NOTE: The vendor has indicated this is not a vulnerability and states "This is a functionality of the software that is limited to a very limited subset of accounts. If you give someone the privilege to execute arbitrary code on your server, they can execute arbitrary code on your server. We provide very clear warnings to users around this functionality and what it provides.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
GiteaGitea Version >= 1.1.0 <= 1.12.5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 93.69% 0.998
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 6.5 8 6.4
AV:N/AC:L/Au:S/C:P/I:P/A:P
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

https://github.com/go-gitea/gitea/releases
Third Party Advisory
Release Notes
http://packetstormsecurity.com/files/162122/Gitea-Git-Hooks-Remote-Code-Execution.html
Third Party Advisory
Exploit
VDB Entry
https://docs.github.com/en/enterprise-server%402.19/admin/policies/creating-a-pre-receive-hook-script
https://docs.gitlab.com/ee/administration/server_hooks.html
Third Party Advisory
https://github.com/PandatiX/CVE-2021-28378
Third Party Advisory
Exploit
https://github.com/PandatiX/CVE-2021-28378#notes
Third Party Advisory
Exploit
https://github.com/go-gitea/gitea/pull/13058
Third Party Advisory
https://www.fzi.de/en/news/news/detail-en/artikel/fsa-2020-3-schwachstelle-in-gitea-1125-und-gogs-0122-ermoeglicht-ausfuehrung-von-code-nach-authent/
Third Party Advisory