Known Vulnerabilities for products from Gitea

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Gitea".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2023-3515 json Open Redirect in GitHub repository go-gitea/gitea prior to 1.19.4. 4.4 - MEDIUM 2023-07-05 2023-07-11
CVE-2022-46685 json In Jenkins Gitea Plugin 1.4.4 and earlier, the implementation of Gitea personal access tokens did not support credentials mas... 4.3 - MEDIUM 2022-12-12 2022-12-12
CVE-2022-42968 json Gitea before 1.17.3 does not sanitize and escape refs in the git backend. Arguments to git commands are mishandled. 9.8 - CRITICAL 2022-10-16 2022-12-03
CVE-2022-38795 json In Gitea through 1.17.1, repo cloning can occur in the migration function. 6.5 - MEDIUM 2023-08-07 2023-08-09
CVE-2022-38183 json In Gitea before 1.16.9, it was possible for users to add existing issues to projects. Due to improper access controls, an att... 6.5 - MEDIUM 2022-08-12 2023-08-08
CVE-2022-30781 json Gitea before 1.16.7 does not escape git fetch remote. 7.5 - HIGH 2022-05-16 2023-01-27
CVE-2022-27313 json An arbitrary file deletion vulnerability in Gitea v1.16.3 allows attackers to cause a Denial of Service (DoS) via deleting th... 7.5 - HIGH 2022-05-03 2022-05-11
CVE-2022-1928 json Cross-site Scripting (XSS) - Stored in GitHub repository go-gitea/gitea prior to 1.16.9. 5.4 - MEDIUM 2022-05-29 2022-11-16
CVE-2022-1058 json Open Redirect on login in GitHub repository go-gitea/gitea prior to 1.16.5. 6.1 - MEDIUM 2022-03-24 2022-03-29
CVE-2022-0905 json Missing Authorization in GitHub repository go-gitea/gitea prior to 1.16.4. 7.1 - HIGH 2022-03-10 2023-06-29
CVE-2021-45331 json An Authentication Bypass vulnerability exists in Gitea before 1.5.0, which could let a malicious user gain privileges. If cap... 9.8 - CRITICAL 2022-02-09 2022-02-14
CVE-2021-45330 json An issue exsits in Gitea through 1.15.7, which could let a malicious user gain privileges due to client side cookies not bein... 9.8 - CRITICAL 2022-02-09 2022-07-12
CVE-2021-45329 json Cross Site Scripting (XSS) vulnerability exists in Gitea before 1.5.1 via the repository settings inside the external wiki/is... 6.1 - MEDIUM 2022-02-08 2022-02-11
CVE-2021-45328 json Gitea before 1.4.3 is affected by URL Redirection to Untrusted Site ('Open Redirect') via internal URLs. 6.1 - MEDIUM 2022-02-08 2022-02-11
CVE-2021-45327 json Gitea before 1.11.2 is affected by Trusting HTTP Permission Methods on the Server Side when referencing the vulnerable admin ... 9.8 - CRITICAL 2022-02-08 2023-08-08
CVE-2021-45326 json Cross Site Request Forgery (CSRF) vulnerability exists in Gitea before 1.5.2 via API routes.This can be dangerous especially ... 8.8 - HIGH 2022-02-08 2022-02-11
CVE-2021-45325 json Server Side Request Forgery (SSRF) vulneraility exists in Gitea before 1.7.0 using the OpenID URL. 7.5 - HIGH 2022-02-08 2022-02-11
CVE-2021-29134 json ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... 5.3 - MEDIUM 2022-03-15 2022-03-22
CVE-2021-28378 json Gitea 1.12.x and 1.13.x before 1.13.4 allows XSS via certain issue data in some situations. 5.4 - MEDIUM 2021-03-15 2021-12-16
CVE-2021-3382 json Stack buffer overflow vulnerability in gitea 1.9.0 through 1.13.1 allows remote attackers to cause a denial of service (crash... 7.5 - HIGH 2021-02-05 2021-02-08

Known software with vulnerabilities from Gitea

Type Vendor Product Version
ApplicationGiteaGitea0.9.99