Описание
Gitea before 1.5.4 allows remote code execution because it does not properly validate session IDs. This is related to session ID handling in the go-macaron/session code for Macaron.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| gitea | removed | package |
Примечания
https://github.com/go-gitea/gitea/issues/5140
EPSS
Процентиль: 91%
0.07092
Низкий
Связанные уязвимости
CVSS3: 9.8
ubuntu
больше 7 лет назад
Gitea before 1.5.4 allows remote code execution because it does not properly validate session IDs. This is related to session ID handling in the go-macaron/session code for Macaron.
CVSS3: 9.8
nvd
больше 7 лет назад
Gitea before 1.5.4 allows remote code execution because it does not properly validate session IDs. This is related to session ID handling in the go-macaron/session code for Macaron.
EPSS
Процентиль: 91%
0.07092
Низкий