PT-2023-25169 · Gitea+1 · Gitea+1

Lafriks

·

Publicado

2023-07-05

·

Atualizado

2024-08-20

·

CVE-2023-3515

CVSS v3.1

3.0

Baixa

VetorAV:N/AC:H/PR:L/UI:R/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions gitea versions prior to 1.19.4
Description The issue is an Open Redirect vulnerability in the GitHub repository go-gitea/gitea. This vulnerability is most likely a post-auth redirect and is a POST-based request scenario, making it less likely to be exploited or chained with other bugs for phishing or credential theft.
Recommendations For versions prior to 1.19.4, update to version 1.19.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable redirect functionality until a patch is applied.

Exploit

Correção

Open Redirect

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2023-4568
ALT-PU-2023-4588
ALT-PU-2024-3792
BIT-GITEA-2023-3515
CVE-2023-3515
GHSA-CF6V-9J57-V6R6
GO-2023-1894

Produtos afetados

Alt Linux
Gitea