VYPR

Gitea

by Go Gitea

Source repositories

CVEs (146)

  • CVE-2020-28991CriNov 24, 2020
    risk 0.00cvss 9.8epss 0.02

    Gitea 0.9.99 through 1.12.x before 1.12.6 does not prevent a git protocol path that specifies a TCP port number and also contains newlines (with URL encoding) in ParseRemoteAddr in modules/auth/repo_form.go.

  • CVE-2020-13246HigMay 20, 2020
    risk 0.00cvss 7.5epss 0.02

    An issue was discovered in Gitea through 1.11.5. An attacker can trigger a deadlock by initiating a transfer of a repository's ownership from one organization to another.

  • CVE-2019-1010261MedJul 18, 2019
    risk 0.00cvss 6.1epss 0.01

    Gitea 1.7.0 and earlier is affected by: Cross Site Scripting (XSS). The impact is: Attacker is able to have victim execute arbitrary JS in browser. The component is: go-get URL generation - PR to fix: https://github.com/go-gitea/gitea/pull/5905. The attack vector is: victim must…

  • CVE-2019-11576CriApr 28, 2019
    risk 0.00cvss 9.8epss 0.02

    Gitea before 1.8.0 allows 1FA for user accounts that have completed 2FA enrollment. If a user's credentials are known, then an attacker could send them to the API without requiring the 2FA one-time password.

  • CVE-2019-11228HigApr 15, 2019
    risk 0.00cvss 7.5epss 0.01

    repo/setting.go in Gitea before 1.7.6 and 1.8.x before 1.8-RC3 does not validate the form.MirrorAddress before calling SaveAddress.

  • CVE-2019-1000002MedFeb 4, 2019
    risk 0.00cvss 6.5epss 0.01

    Gitea version 1.6.2 and earlier contains a Incorrect Access Control vulnerability in Delete/Edit file functionallity that can result in the attacker deleting files outside the repository he/she has access to. This attack appears to be exploitable via the attacker must get write…

Page 8 of 8