PT-2022-18374 · Gitea · Gitea
Published
2022-05-03
·
Updated
2024-08-21
·
CVE-2022-27313
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Gitea version 1.16.3
Description
The issue allows attackers to cause a Denial of Service (DoS) via deleting the configuration file. This is due to an arbitrary file deletion vulnerability.
Recommendations
For Gitea version 1.16.3, update to a version that fixes this issue to prevent arbitrary file deletion and potential Denial of Service (DoS) attacks.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gitea