HIGH 7.5 Go
Shell command injection in gitea
GHSA-p5f9-c9j9-g8qx · BIT-gitea-2022-30781 · CVE-2022-30781 · GO-2022-0450
Published · Modified
Description
Gitea before 1.16.7 does not escape the shell out for git fetch remote allowing for shell command injection
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2022-30781
- WEB https://github.com/go-gitea/gitea/pull/19487
- WEB https://github.com/go-gitea/gitea/pull/19490
- WEB https://blog.gitea.io/2022/05/gitea-1.16.7-is-released
- PACKAGE https://github.com/go-gitea/gitea
- WEB http://packetstormsecurity.com/files/168400/Gitea-1.16.6-Remote-Code-Execution.html
- WEB http://packetstormsecurity.com/files/169928/Gitea-Git-Fetch-Remote-Code-Execution.html
Ready to move
Start Securing
Free, no credit card | First findings in minutes