Описание
An issue exsits in Gitea through 1.15.7, which could let a malicious user gain privileges due to client side cookies not being deleted and the session remains valid on the server side for reuse.
Ссылки
- Issue TrackingThird Party Advisory
- Issue TrackingThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.15.7 (включая)
cpe:2.3:a:gitea:gitea:*:*:*:*:*:*:*:*
EPSS
Процентиль: 78%
0.01128
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-459
Связанные уязвимости
CVSS3: 9.8
debian
почти 4 года назад
An issue exsits in Gitea through 1.15.7, which could let a malicious u ...
EPSS
Процентиль: 78%
0.01128
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-459