QID 730673

Date Published: 2022-12-01

QID 730673: Gitea Remote Code Execution (RCE) Vulnerability

Gitea is an open-source forge software package for hosting software development version control using Git as well as other collaborative features like bug tracking, wikis and code review.

CVE-2022-30781: Gitea before 1.16.7 does not escape git fetch remote.

Affected Versions: Gitea versions prior to 1.16.7

QID Detection Logic (Unauthenticated): Looks for Gitea version on the web root page and flags if vulnerable.

Successful exploitation of this vulnerability may allow an attacker to execute arbitrary code on the target system.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Customers are advised to update to latest Gitea Downloads.
    Vendor References

    CVEs related to QID 730673

    Software Advisories
    Advisory ID Software Component Link
    Gitea Blog URL Logo blog.gitea.io/2022/05/gitea-1.16.7-is-released/