PT-2020-13393 · Gitea+1 · Gitea+1

Published

2020-05-20

·

Updated

2024-08-21

·

CVE-2020-13246

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Gitea versions through 1.11.5
Description An issue was discovered in Gitea where an attacker can trigger a deadlock by initiating a transfer of a repository's ownership from one organization to another.
Recommendations For Gitea versions through 1.11.5, as a temporary workaround, consider restricting the ability to transfer repository ownership between organizations until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Locking

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2233
ALT-PU-2020-2344
BIT-GITEA-2020-13246
CVE-2020-13246
GHSA-G2QX-6GHW-67HM
GO-2022-0830

Affected Products

Alt Linux
Gitea