VYPR
High severity8.8OSV Advisory· Published Apr 15, 2019· Updated Jun 17, 2026

CVE-2019-11229

CVE-2019-11229

Description

models/repo_mirror.go in Gitea before 1.7.6 and 1.8.x before 1.8-RC3 mishandles mirror repo URL settings, leading to remote code execution.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/go-gitea/giteaGo
< 1.7.61.7.6

Affected products

5
  • ghsa-coords
    Range: < 1.7.6
  • Go Gitea/GiteaOSV4 versions
    v0.9.99, v1.0.0, v1.1.0, …+ 3 more
    • (no CPE)range: v0.9.99, v1.0.0, v1.1.0, …
    • cpe:2.3:a:gitea:gitea:*:*:*:*:*:*:*:*range: <1.7.6
    • cpe:2.3:a:gitea:gitea:1.8.0:rc1:*:*:*:*:*:*
    • cpe:2.3:a:gitea:gitea:1.8.0:rc2:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

8

News mentions

0

No linked articles in our index yet.