ALT-PU-2022-1884-2
Closed vulnerabilities
Published: 2022-05-16
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2022-30781
Gitea before 1.16.7 does not escape git fetch remote.
Severity: MEDIUM (5.0)Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N
Severity: HIGH (7.5)Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
References:
- http://packetstormsecurity.com/files/168400/Gitea-1.16.6-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/169928/Gitea-Git-Fetch-Remote-Code-Execution.html
- https://blog.gitea.io/2022/05/gitea-1.16.7-is-released/
- https://github.com/go-gitea/gitea/pull/19487
- https://github.com/go-gitea/gitea/pull/19490
- http://packetstormsecurity.com/files/168400/Gitea-1.16.6-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/169928/Gitea-Git-Fetch-Remote-Code-Execution.html
- https://blog.gitea.io/2022/05/gitea-1.16.7-is-released/
- https://github.com/go-gitea/gitea/pull/19487
- https://github.com/go-gitea/gitea/pull/19490
Published: 2022-05-17
Modified: 2022-05-25
Modified: 2022-05-25
GHSA-p5f9-c9j9-g8qx
Shell command injection in gitea
Severity: HIGH (7.5)Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
References:
- https://nvd.nist.gov/vuln/detail/CVE-2022-30781
- https://github.com/go-gitea/gitea/pull/19487
- https://github.com/go-gitea/gitea/pull/19490
- https://blog.gitea.io/2022/05/gitea-1.16.7-is-released
- https://github.com/go-gitea/gitea
- http://packetstormsecurity.com/files/168400/Gitea-1.16.6-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/169928/Gitea-Git-Fetch-Remote-Code-Execution.html
