PT-2022-12322 · Gitea+1 · Gitea+1

Ghost

·

Published

2022-01-22

·

Updated

2024-08-21

·

CVE-2021-45330

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Gitea versions prior to 1.15.8
Description The issue exists due to client-side cookies not being deleted, and the session remains valid on the server side for reuse, allowing a malicious user to gain privileges. This is related to improper privilege management in Gitea.
Recommendations For versions prior to 1.15.8, update to version 1.15.8 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive operations that rely on proper session management until a patch is applied.

Fix

Improper Privilege Management

Weakness Enumeration

Related Identifiers

ALT-PU-2022-1116
ALT-PU-2022-1210
ALT-PU-2022-3074
BIT-GITEA-2021-45330
CVE-2021-45330
GHSA-PG38-R834-G45J
GO-2022-0982

Affected Products

Alt Linux
Gitea