CVE-2022-0905
- EPSS 0.29%
- Veröffentlicht 10.03.2022 15:15:10
- Zuletzt bearbeitet 21.11.2024 06:39:38
Missing Authorization in GitHub repository go-gitea/gitea prior to 1.16.4.
CVE-2021-45331
- EPSS 0.23%
- Veröffentlicht 09.02.2022 18:15:10
- Zuletzt bearbeitet 21.11.2024 06:32:05
An Authentication Bypass vulnerability exists in Gitea before 1.5.0, which could let a malicious user gain privileges. If captured, the TOTP code for the 2FA can be submitted correctly more than once.
CVE-2021-45330
- EPSS 1.13%
- Veröffentlicht 09.02.2022 18:15:09
- Zuletzt bearbeitet 21.11.2024 06:32:05
An issue exsits in Gitea through 1.15.7, which could let a malicious user gain privileges due to client side cookies not being deleted and the session remains valid on the server side for reuse.
CVE-2021-45329
- EPSS 0.4%
- Veröffentlicht 08.02.2022 23:15:07
- Zuletzt bearbeitet 21.11.2024 06:32:05
Cross Site Scripting (XSS) vulnerability exists in Gitea before 1.5.1 via the repository settings inside the external wiki/issue tracker URL field.
CVE-2021-45328
- EPSS 0.18%
- Veröffentlicht 08.02.2022 16:15:07
- Zuletzt bearbeitet 21.11.2024 06:32:05
Gitea before 1.4.3 is affected by URL Redirection to Untrusted Site ('Open Redirect') via internal URLs.
CVE-2021-45327
- EPSS 0.87%
- Veröffentlicht 08.02.2022 15:15:07
- Zuletzt bearbeitet 21.11.2024 06:32:05
Gitea before 1.11.2 is affected by Trusting HTTP Permission Methods on the Server Side when referencing the vulnerable admin or user API. which could let a remote malisious user execute arbitrary code.
CVE-2021-45326
- EPSS 0.21%
- Veröffentlicht 08.02.2022 15:15:07
- Zuletzt bearbeitet 21.11.2024 06:32:05
Cross Site Request Forgery (CSRF) vulnerability exists in Gitea before 1.5.2 via API routes.This can be dangerous especially with state altering POST requests.
CVE-2021-45325
- EPSS 0.3%
- Veröffentlicht 08.02.2022 15:15:07
- Zuletzt bearbeitet 21.11.2024 06:32:05
Server Side Request Forgery (SSRF) vulneraility exists in Gitea before 1.7.0 using the OpenID URL.
CVE-2021-28378
- EPSS 12.92%
- Veröffentlicht 15.03.2021 06:15:12
- Zuletzt bearbeitet 21.11.2024 05:59:36
Gitea 1.12.x and 1.13.x before 1.13.4 allows XSS via certain issue data in some situations.
CVE-2021-3382
- EPSS 0.92%
- Veröffentlicht 05.02.2021 16:15:12
- Zuletzt bearbeitet 21.11.2024 06:21:23
Stack buffer overflow vulnerability in gitea 1.9.0 through 1.13.1 allows remote attackers to cause a denial of service (crash) via vectors related to a file path.