PT-2019-12388 · Gitea+1 · Gitea+1

Techknowlogick

·

Published

2019-04-26

·

Updated

2022-05-24

·

CVE-2019-11576

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Gitea versions prior to 1.8.0
Description The issue allows for 1-factor authentication (1FA) for user accounts that have completed 2-factor authentication (2FA) enrollment. If a user's credentials are known, an attacker could send them to the API without requiring the 2FA one-time password. This could potentially lead to unauthorized access.
Recommendations For versions prior to 1.8.0, update to version 1.8.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the API or requiring additional authentication measures until the update can be applied.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1741
CVE-2019-11576
GHSA-3393-R4P5-VHQH

Affected Products

Alt Linux
Gitea