CVE-2021-45327

Name
CVE-2021-45327
Description
Gitea before 1.11.2 is affected by Trusting HTTP Permission Methods on the Server Side when referencing the vulnerable admin or user API. which could let a remote malisious user execute arbitrary code.
NVD Severity
high
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://github.com/go-gitea/gitea/pull/10465
MISC https://blog.gitea.io/2020/03/gitea-1.11.2-is-released/
MISC https://github.com/go-gitea/gitea/pull/10582
MISC https://github.com/go-gitea/gitea/pull/10462

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:gitea:gitea:*:*:*:*:*:*:*:* gitea >= None < 1.11.2

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
gitea edge-community 1.11.2-r0 None fixed
gitea edge-community 1.5.2-r0 None possibly vulnerable
gitea edge-community 1.5.1-r0 None possibly vulnerable
gitea 3.22-community 1.11.2-r0 None fixed
gitea 3.22-community 1.5.2-r0 None possibly vulnerable
gitea 3.22-community 1.5.1-r0 None possibly vulnerable
gitea 3.21-community 1.11.2-r0 None fixed
gitea 3.20-community 1.11.2-r0 None fixed
gitea 3.19-community 1.11.2-r0 None fixed
gitea 3.18-community 1.11.2-r0 None fixed
gitea 3.17-community 1.11.2-r0 None fixed