Описание
Gitea Remote Code Execution
models/repo_mirror.go in Gitea before 1.7.6 and 1.8.x before 1.8-RC3 mishandles mirror repo URL settings, leading to remote code execution.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2019-11229
- https://github.com/go-gitea/gitea/pull/6593
- https://github.com/go-gitea/gitea/pull/6595
- https://github.com/go-gitea/gitea/releases/tag/v1.7.6
- https://github.com/go-gitea/gitea/releases/tag/v1.8.0-rc3
- https://www.exploit-db.com/exploits/49383
- http://packetstormsecurity.com/files/160833/Gitea-1.7.5-Remote-Code-Execution.html
Пакеты
Наименование
github.com/go-gitea/gitea
go
Затронутые версииВерсия исправления
< 1.7.6
1.7.6
Связанные уязвимости
CVSS3: 8.8
nvd
почти 7 лет назад
models/repo_mirror.go in Gitea before 1.7.6 and 1.8.x before 1.8-RC3 mishandles mirror repo URL settings, leading to remote code execution.
CVSS3: 8.8
debian
почти 7 лет назад
models/repo_mirror.go in Gitea before 1.7.6 and 1.8.x before 1.8-RC3 m ...