PT-2022-6562 · Gitea · Gitea

Beeonthego

+2

·

Published

2022-02-08

·

Updated

2024-08-21

·

CVE-2021-45326

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Gitea versions prior to 1.5.2
Description The issue is related to a Cross Site Request Forgery (CSRF) vulnerability in the Gitea Git repository management system interface. This vulnerability can be exploited by a remote attacker to perform a CSRF attack by sending specially crafted POST requests, potentially altering the state of the system. The vulnerability is particularly dangerous with state-altering POST requests.
Recommendations For versions prior to 1.5.2, update to version 1.5.2 or later to resolve the issue. As a temporary workaround, consider restricting access to API routes to minimize the risk of exploitation. Avoid using state-altering POST requests in the affected API routes until the issue is resolved.

Fix

CSRF

Weakness Enumeration

Related Identifiers

BDU:2023-02417
BIT-GITEA-2021-45326
CVE-2021-45326
GHSA-4WP3-8Q92-MH8W
GO-2022-0309

Affected Products

Gitea