QID 730523

Date Published: 2022-06-16

QID 730523: Gitea Authentication Bypass Vulnerability

Gitea is an open-source forge software package for hosting software development version control using Git as well as other collaborative features like bug tracking, wikis and code review.

CVE-2021-45331: An Authentication Bypass vulnerability exists in Gitea before 1.5.0, which could let a malicious user gain privileges. If captured, the TOTP code for the 2FA can be submitted correctly more than once.

Affected Versions: Gitea versions prior to 1.5.0

QID Detection Logic (Unauthenticated): Looks for Gitea version on the web root page and flags if vulnerable.

Successful exploitation of this vulnerability may allow an unauthorized attacker to gain user privileges.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Customers are advised to update to latest Gitea Version.
    Vendor References

    CVEs related to QID 730523

    Software Advisories
    Advisory ID Software Component Link
    Gitea Blog URL Logo blog.gitea.io/2018/08/gitea-1.5.0-is-released/