Known Vulnerabilities for products from Gitea
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Gitea".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-3515 json | Open Redirect in GitHub repository go-gitea/gitea prior to 1.19.4. | 4.4 - MEDIUM | 2023-07-05 | 2023-07-11 |
| CVE-2022-46685 json | In Jenkins Gitea Plugin 1.4.4 and earlier, the implementation of Gitea personal access tokens did not support credentials mas... | 4.3 - MEDIUM | 2022-12-12 | 2022-12-12 |
| CVE-2022-42968 json | Gitea before 1.17.3 does not sanitize and escape refs in the git backend. Arguments to git commands are mishandled. | 9.8 - CRITICAL | 2022-10-16 | 2022-12-03 |
| CVE-2022-38795 json | In Gitea through 1.17.1, repo cloning can occur in the migration function. | 6.5 - MEDIUM | 2023-08-07 | 2023-08-09 |
| CVE-2022-38183 json | In Gitea before 1.16.9, it was possible for users to add existing issues to projects. Due to improper access controls, an att... | 6.5 - MEDIUM | 2022-08-12 | 2023-08-08 |
| CVE-2022-30781 json | Gitea before 1.16.7 does not escape git fetch remote. | 7.5 - HIGH | 2022-05-16 | 2023-01-27 |
| CVE-2022-27313 json | An arbitrary file deletion vulnerability in Gitea v1.16.3 allows attackers to cause a Denial of Service (DoS) via deleting th... | 7.5 - HIGH | 2022-05-03 | 2022-05-11 |
| CVE-2022-1928 json | Cross-site Scripting (XSS) - Stored in GitHub repository go-gitea/gitea prior to 1.16.9. | 5.4 - MEDIUM | 2022-05-29 | 2022-11-16 |
| CVE-2022-1058 json | Open Redirect on login in GitHub repository go-gitea/gitea prior to 1.16.5. | 6.1 - MEDIUM | 2022-03-24 | 2022-03-29 |
| CVE-2022-0905 json | Missing Authorization in GitHub repository go-gitea/gitea prior to 1.16.4. | 7.1 - HIGH | 2022-03-10 | 2023-06-29 |
| CVE-2021-45331 json | An Authentication Bypass vulnerability exists in Gitea before 1.5.0, which could let a malicious user gain privileges. If cap... | 9.8 - CRITICAL | 2022-02-09 | 2022-02-14 |
| CVE-2021-45330 json | An issue exsits in Gitea through 1.15.7, which could let a malicious user gain privileges due to client side cookies not bein... | 9.8 - CRITICAL | 2022-02-09 | 2022-07-12 |
| CVE-2021-45329 json | Cross Site Scripting (XSS) vulnerability exists in Gitea before 1.5.1 via the repository settings inside the external wiki/is... | 6.1 - MEDIUM | 2022-02-08 | 2022-02-11 |
| CVE-2021-45328 json | Gitea before 1.4.3 is affected by URL Redirection to Untrusted Site ('Open Redirect') via internal URLs. | 6.1 - MEDIUM | 2022-02-08 | 2022-02-11 |
| CVE-2021-45327 json | Gitea before 1.11.2 is affected by Trusting HTTP Permission Methods on the Server Side when referencing the vulnerable admin ... | 9.8 - CRITICAL | 2022-02-08 | 2023-08-08 |
| CVE-2021-45326 json | Cross Site Request Forgery (CSRF) vulnerability exists in Gitea before 1.5.2 via API routes.This can be dangerous especially ... | 8.8 - HIGH | 2022-02-08 | 2022-02-11 |
| CVE-2021-45325 json | Server Side Request Forgery (SSRF) vulneraility exists in Gitea before 1.7.0 using the OpenID URL. | 7.5 - HIGH | 2022-02-08 | 2022-02-11 |
| CVE-2021-29134 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 5.3 - MEDIUM | 2022-03-15 | 2022-03-22 |
| CVE-2021-28378 json | Gitea 1.12.x and 1.13.x before 1.13.4 allows XSS via certain issue data in some situations. | 5.4 - MEDIUM | 2021-03-15 | 2021-12-16 |
| CVE-2021-3382 json | Stack buffer overflow vulnerability in gitea 1.9.0 through 1.13.1 allows remote attackers to cause a denial of service (crash... | 7.5 - HIGH | 2021-02-05 | 2021-02-08 |
Known software with vulnerabilities from Gitea
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Gitea | Gitea | 0.9.99 |