PT-2022-6563 · Gitea+1 · Gitea+1

Zeripath

·

Published

2019-01-31

·

Updated

2024-08-21

·

CVE-2021-45325

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Gitea versions prior to 1.7.0
Description A Server Side Request Forgery (SSRF) issue exists, allowing a remote attacker to exploit the vulnerability using a specially crafted OpenID URL. This can lead to sensitive information about the local network being leaked through the error provided by the UI.
Recommendations For versions prior to 1.7.0, update to version 1.7.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the OpenID URL to minimize the risk of exploitation.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1153
BDU:2023-02418
BIT-GITEA-2021-45325
CVE-2021-45325
GHSA-8H8P-X289-VVQR
GO-2022-0308

Affected Products

Alt Linux
Gitea