PT-2023-25169 · Gitea+1 · Gitea+1

Lafriks

·

Published

2023-07-05

·

Updated

2024-08-20

·

CVE-2023-3515

CVSS v3.1

3.0

Low

VectorAV:N/AC:H/PR:L/UI:R/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions gitea versions prior to 1.19.4
Description The issue is an Open Redirect vulnerability in the GitHub repository go-gitea/gitea. This vulnerability is most likely a post-auth redirect and is a POST-based request scenario, making it less likely to be exploited or chained with other bugs for phishing or credential theft.
Recommendations For versions prior to 1.19.4, update to version 1.19.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable redirect functionality until a patch is applied.

Exploit

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2023-4568
ALT-PU-2023-4588
ALT-PU-2024-3792
BIT-GITEA-2023-3515
CVE-2023-3515
GHSA-CF6V-9J57-V6R6
GO-2023-1894

Affected Products

Alt Linux
Gitea