PT-2019-12203 · Gitea+1 · Gitea+1

Published

2019-04-13

·

Updated

2024-08-21

·

CVE-2019-11229

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Gitea versions 1.7.0 through 1.7.5 Gitea versions 1.8.0 through 1.8-RC2
Description The issue arises from the mishandling of mirror repository URL settings in the models/repo mirror.go file, leading to remote code execution. This allows an attacker to potentially execute arbitrary code on the affected system.
Recommendations For Gitea versions 1.7.0 through 1.7.5, update to version 1.7.6 or later. For Gitea versions 1.8.0 through 1.8-RC2, update to version 1.8-RC3 or later.

Exploit

Fix

Code Injection

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1639
CVE-2019-11229
GHSA-HPMR-PRR2-CQC4
GO-2022-0846

Affected Products

Alt Linux
Gitea