ALT-PU-2024-3792-4
Closed vulnerabilities
Published: 2023-08-07
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2022-38795
In Gitea through 1.17.1, repo cloning can occur in the migration function.
Severity: MEDIUM (6.5)Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
References:
Published: 2022-10-16
Modified: 2025-05-14
Modified: 2025-05-14
CVE-2022-42968
Gitea before 1.17.3 does not sanitize and escape refs in the git backend. Arguments to git commands are mishandled.
Severity: CRITICAL (9.8)Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References:
Published: 2023-07-05
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2023-3515
Open Redirect in GitHub repository go-gitea/gitea prior to 1.19.4.
Severity: MEDIUM (4.4)Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N
References:
- https://github.com/go-gitea/gitea/commit/9aaaf980f0ba15611f30568bd67bce3ec12954e2
- https://huntr.dev/bounties/e335cd18-bc4d-4585-adb7-426c817ed053
- https://security.gentoo.org/glsa/202312-13
- https://github.com/go-gitea/gitea/commit/9aaaf980f0ba15611f30568bd67bce3ec12954e2
- https://huntr.dev/bounties/e335cd18-bc4d-4585-adb7-426c817ed053
- https://security.gentoo.org/glsa/202312-13
Published: 2025-12-26
Modified: 2025-12-31
Modified: 2025-12-31
CVE-2025-68946
In Gitea before 1.20.1, a forbidden URL scheme such as javascript: can be used for a link, aka XSS.
Severity: MEDIUM (5.4)Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
References:
Published: 2023-08-07
Modified: 2023-08-09
Modified: 2023-08-09
GHSA-8j3v-68w3-3848
Gitea erroneous repo clones
Severity: MEDIUM (6.5)Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
References:
Published: 2023-07-05
Modified: 2023-07-06
Modified: 2023-07-06
GHSA-cf6v-9j57-v6r6
code.gitea.io/gitea Open Redirect vulnerability
Severity: LOW (3.0)Vector: CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:N/A:N
References:
Published: 2025-12-26
Modified: 2025-12-26
Modified: 2025-12-26
GHSA-hq57-c72x-4774
Gitea vulnerable to Cross-site Scripting
Severity: MEDIUM (5.4)Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
References:
Published: 2022-10-16
Modified: 2022-10-21
Modified: 2022-10-21
GHSA-w8xw-7crf-h23x
Gitea vulnerable to Argument Injection
Severity: CRITICAL (9.8)Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References:
