QID 730524

Date Published: 2022-06-16

QID 730524: Gitea Improper Session Handling Vulnerability

Gitea is an open-source forge software package for hosting software development version control using Git as well as other collaborative features like bug tracking, wikis and code review.

CVE-2021-45330: An issue exsits in Gitea through 1.15.7, which could let a malicious user gain privileges due to client side cookies not being deleted and the session remains valid on the server side for reuse.

Affected Versions: Gitea versions prior to 1.15.8

QID Detection Logic (Unauthenticated): Looks for Gitea version on the web root page and flags if vulnerable.

Successful exploitation of this vulnerability may allow an unauthorized attacker to gain user privileges.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Customers are advised to update to latest Gitea Version.
    Vendor References

    CVEs related to QID 730524

    Software Advisories
    Advisory ID Software Component Link
    Gitea Blog URL Logo blog.gitea.io/2021/12/gitea-1.15.7-is-released/