Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-42968

Опубликовано: 16 окт. 2022
Источник: redhat
CVSS3: 9.8

Описание

Gitea before 1.17.3 does not sanitize and escape refs in the git backend. Arguments to git commands are mishandled.

A flaw was found in Gitea. The self-hosted Git service does not sanitize and escape refs in the git backend. This issue could allow an attacker to craft arguments for the git commands, which will be mishandled.

Отчет

The 'gitea' package is a transitive dependency in the Red Hat products and is not used directly in a codebase, which reduces the chances of successful exploitation. Hence, the impact is set as Moderate.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/lokistack-gateway-rhel9Not affected
OpenShift Serverlessopenshift-serverless-1/client-kn-rhel8Not affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/acm-search-v2-rhel8Not affected
Red Hat Advanced Cluster Security 3advanced-cluster-security/rhacs-main-rhel8Not affected
Red Hat Advanced Cluster Security 3advanced-cluster-security/rhacs-scanner-rhel8Not affected
Red Hat OpenShift GitOpsopenshift-gitops-1/kam-delivery-rhel8Not affected
Red Hat OpenShift GitOpsopenshift-gitops-kamNot affected
Red Hat Quay 3quay/quay-builder-rhel8Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=2135739gitea: Sanitize and Escape refs in git backend

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
больше 3 лет назад

Gitea before 1.17.3 does not sanitize and escape refs in the git backend. Arguments to git commands are mishandled.

CVSS3: 9.8
debian
больше 3 лет назад

Gitea before 1.17.3 does not sanitize and escape refs in the git backe ...

CVSS3: 9.8
github
больше 3 лет назад

Gitea vulnerable to Argument Injection

9.8 Critical

CVSS3