Show filters
34 Total Results
Displaying 31-34 of 34
Sort by:
Attacker Value
Unknown
CVE-2019-1000002
Disclosure Date: February 04, 2019 (last updated November 27, 2024)
Gitea version 1.6.2 and earlier contains a Incorrect Access Control vulnerability in Delete/Edit file functionallity that can result in the attacker deleting files outside the repository he/she has access to. This attack appears to be exploitable via the attacker must get write access to "any" repository including self-created ones.. This vulnerability appears to have been fixed in 1.6.3, 1.7.0-rc2.
0
Attacker Value
Unknown
CVE-2018-18926
Disclosure Date: November 04, 2018 (last updated November 27, 2024)
Gitea before 1.5.4 allows remote code execution because it does not properly validate session IDs. This is related to session ID handling in the go-macaron/session code for Macaron.
0
Attacker Value
Unknown
CVE-2018-1000803
Disclosure Date: October 08, 2018 (last updated November 27, 2024)
Gitea version prior to version 1.5.1 contains a CWE-200 vulnerability that can result in Exposure of users private email addresses. This attack appear to be exploitable via Watch a repository to receive email notifications. Emails received contain the other recipients even if they have the email set as private. This vulnerability appears to have been fixed in 1.5.1.
0
Attacker Value
Unknown
CVE-2018-15192
Disclosure Date: August 08, 2018 (last updated November 27, 2024)
An SSRF vulnerability in webhooks in Gitea through 1.5.0-rc2 and Gogs through 0.11.53 allows remote attackers to access intranet services.
0