HIGH 8.1 Go
Gitea Remote Code Execution
GHSA-hpmr-prr2-cqc4 · CVE-2019-11229 · GO-2022-0846
Published · Modified
Description
models/repo_mirror.go in Gitea before 1.7.6 and 1.8.x before 1.8-RC3 mishandles mirror repo URL settings, leading to remote code execution.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2019-11229
- WEB https://github.com/go-gitea/gitea/pull/6593
- WEB https://github.com/go-gitea/gitea/pull/6595
- WEB https://github.com/go-gitea/gitea/releases/tag/v1.7.6
- WEB https://github.com/go-gitea/gitea/releases/tag/v1.8.0-rc3
- WEB https://www.exploit-db.com/exploits/49383
- WEB http://packetstormsecurity.com/files/160833/Gitea-1.7.5-Remote-Code-Execution.html
Ready to move
Start Securing
Free, no credit card | First findings in minutes