Vulnerability index

Browse CVEs

48 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Gitea CRITICAL 9.8
CVE-2021-45327

Gitea before 1.11.2 is affected by Trusting HTTP Permission Methods on the Server Side when referencing the vulnerable admin or user API. which could…

Fix: 1.11.2+
Fix from $2,300 2022-02-08
Gitea HIGH 8.8
CVE-2021-45326

Cross Site Request Forgery (CSRF) vulnerability exists in Gitea before 1.5.2 via API routes.This can be dangerous especially with state altering POST…

Fix: 1.5.2+
Fix from $1,950 2022-02-08
Gitea HIGH 7.5
CVE-2021-45325

Server Side Request Forgery (SSRF) vulneraility exists in Gitea before 1.7.0 using the OpenID URL.

Fix: 1.7.0+
Fix from $1,950 2022-02-08
Gitea MEDIUM 5.4
CVE-2021-28378EPSS 9%

Gitea 1.12.x and 1.13.x before 1.13.4 allows XSS via certain issue data in some situations.

Fix: 1.13.4+
Fix from $1,600 2021-03-15
Gitea HIGH 7.5
CVE-2021-3382

Stack buffer overflow vulnerability in gitea 1.9.0 through 1.13.1 allows remote attackers to cause a denial of service (crash) via vectors related to…

Fix: after 1.13.1
Fix from $1,950 2021-02-05
Gitea CRITICAL 9.8
CVE-2020-28991

Gitea 0.9.99 through 1.12.x before 1.12.6 does not prevent a git protocol path that specifies a TCP port number and also contains newlines (with URL …

Fix: 1.12.6+
Fix from $2,300 2020-11-24
Gitea HIGH 7.2
CVE-2020-14144EPSS 95%

The git hook feature in Gitea 1.1.0 through 1.12.5 might allow for authenticated remote code execution in customer environments where the documentati…

Fix: after 1.12.5
Fix from $1,950 2020-10-16
Gitea HIGH 7.5
CVE-2020-13246

An issue was discovered in Gitea through 1.11.5. An attacker can trigger a deadlock by initiating a transfer of a repository's ownership from one org…

Fix: after 1.11.5
Fix from $1,950 2020-05-20
Gitea MEDIUM 6.1
CVE-2019-1010261

Gitea 1.7.0 and earlier is affected by: Cross Site Scripting (XSS). The impact is: Attacker is able to have victim execute arbitrary JS in browser. T…

Fix: after 1.7.0
Fix from $1,600 2019-07-18
Gitea MEDIUM 6.1
CVE-2019-1010314

Gitea 1.7.2, 1.7.3 is affected by: Cross Site Scripting (XSS). The impact is: execute JavaScript in victim's browser, when the vulnerable repo page i…

Mitigation only
Fix from $1,600 2019-07-11
Gitea HIGH 7.5
CVE-2019-10330

Jenkins Gitea Plugin 1.1.1 and earlier did not implement trusted revisions, allowing attackers without commit access to the Git repo to change Jenkin…

Fix: after 1.1.1
Fix from $1,950 2019-05-31
Gitea CRITICAL 9.8
CVE-2019-11576

Gitea before 1.8.0 allows 1FA for user accounts that have completed 2FA enrollment. If a user's credentials are known, then an attacker could send th…

Fix: 1.8.0+
Fix from $2,300 2019-04-28
Gitea HIGH 8.8
CVE-2019-11229EPSS 55%

models/repo_mirror.go in Gitea before 1.7.6 and 1.8.x before 1.8-RC3 mishandles mirror repo URL settings, leading to remote code execution.

Fix: 1.7.6+
Fix from $1,950 2019-04-15
Gitea HIGH 7.5
CVE-2019-11228

repo/setting.go in Gitea before 1.7.6 and 1.8.x before 1.8-RC3 does not validate the form.MirrorAddress before calling SaveAddress.

Fix: 1.7.6+
Fix from $1,950 2019-04-15
Gitea MEDIUM 6.5
CVE-2019-1000002

Gitea version 1.6.2 and earlier contains a Incorrect Access Control vulnerability in Delete/Edit file functionallity that can result in the attacker …

Fix: after 1.6.2
Fix from $1,600 2019-02-04
Gitea CRITICAL 9.8
CVE-2018-18926

Gitea before 1.5.4 allows remote code execution because it does not properly validate session IDs. This is related to session ID handling in the go-m…

Fix: 1.5.4+
Fix from $2,300 2018-11-04
Gitea MEDIUM 5.3
CVE-2018-1000803

Gitea version prior to version 1.5.1 contains a CWE-200 vulnerability that can result in Exposure of users private email addresses. This attack appea…

Fix: 1.5.1+
Fix from $1,600 2018-10-08
Gitea HIGH 8.6
CVE-2018-15192

An SSRF vulnerability in webhooks in Gitea through 1.5.0-rc2 and Gogs through 0.11.53 allows remote attackers to access intranet services.

Fix: 1.5.0+
Fix from $1,950 2018-08-08