High severity8.8OSV Advisory· Published Apr 15, 2019· Updated Jun 17, 2026
CVE-2019-11229
CVE-2019-11229
Description
models/repo_mirror.go in Gitea before 1.7.6 and 1.8.x before 1.8-RC3 mishandles mirror repo URL settings, leading to remote code execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/go-gitea/giteaGo | < 1.7.6 | 1.7.6 |
Affected products
5Patches
Vulnerability mechanics
References
8- packetstormsecurity.com/files/160833/Gitea-1.7.5-Remote-Code-Execution.htmlnvdExploitThird Party AdvisoryVDB EntryWEB
- github.com/advisories/GHSA-hpmr-prr2-cqc4ghsaADVISORY
- github.com/go-gitea/gitea/releases/tag/v1.7.6nvdRelease NotesThird Party AdvisoryWEB
- github.com/go-gitea/gitea/releases/tag/v1.8.0-rc3nvdRelease NotesThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2019-11229ghsaADVISORY
- github.com/go-gitea/gitea/pull/6593ghsaWEB
- github.com/go-gitea/gitea/pull/6595ghsaWEB
- www.exploit-db.com/exploits/49383ghsaWEB
News mentions
0No linked articles in our index yet.