VYPR

Bitnami package

gitea

pkg:bitnami/gitea

Vulnerabilities (43)

  • CVE-2020-28991CriNov 24, 2020
    affected >= 0.9.99, < 1.12.6fixed 1.12.6

    Gitea 0.9.99 through 1.12.x before 1.12.6 does not prevent a git protocol path that specifies a TCP port number and also contains newlines (with URL encoding) in ParseRemoteAddr in modules/auth/repo_form.go.

  • CVE-2020-14144HigOct 16, 2020
    affected >= 1.1.0, < 1.12.6fixed 1.12.6

    The git hook feature in Gitea 1.1.0 through 1.12.5 might allow for authenticated remote code execution in customer environments where the documentation was not understood (e.g., one viewpoint is that the dangerousness of this feature should be documented immediately above the ENA

  • CVE-2020-13246HigMay 20, 2020
    affected < 1.11.6fixed 1.11.6

    An issue was discovered in Gitea through 1.11.5. An attacker can trigger a deadlock by initiating a transfer of a repository's ownership from one organization to another.

Page 3 of 3