Записи Gitea
54 опубликованных записей вендора gitea.
Профиль для исследователя
- Попали в KEV
- 1 · 1,9 %
- С эксплойтом
- 3 · 5,6 %
- Pre-auth RCE
- 4
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- -1 дн.
Повторяющиеся классы
- CWE-284 Improper Access Control8
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')8
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')3
- CWE-862 Missing Authorization3
- CWE-863 Incorrect Authorization3
- CWE-287 Improper Authentication2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
54 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
76На этой неделе | CVE-2026-60004Готовый эксплойт | Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.gitea · gitea · CWE-94 | Критическая9,8 | KEV | 24,0 % | 26 авг. 2026 г. |
57В плане | CVE-2020-14144Готовый эксплойт | The git hook feature in Gitea 1.1.0 through 1.12.5 might allow for authenticated remote code execution in customer environments where the dogitea · gitea · CWE-78 | Высокая7,2 | — | 95,4 % | 16 окт. 2020 г. |
56В плане | CVE-2022-30781Готовый эксплойт | Gitea before 1.16.7 does not escape git fetch remote.gitea · gitea · CWE-116 | Высокая7,5 | — | 87,9 % | 16 мая 2022 г. |
51В плане | CVE-2019-11229Proof of concept | models/repo_mirror.go in Gitea before 1.7.6 and 1.8.x before 1.8-RC3 mishandles mirror repo URL settings, leading to remote code execution.gitea · gitea | Высокая8,8 | — | 55,0 % | 15 апр. 2019 г. |
50В плане | CVE-2024-6886Proof of concept | Inproper Sanitation of field leading to stored XSSgitea · gitea open source git server · CWE-79 | Критическая10,0 | — | 33,0 % | 6 авг. 2024 г. |
40В плане | CVE-2022-1058Proof of concept | Open Redirect on login in go-gitea/giteagitea · gitea · CWE-601 | Средняя6,1 | — | 53,2 % | 24 мар. 2022 г. |
40В плане | CVE-2018-18926Эксплойта нет | Gitea before 1.5.4 allows remote code execution because it does not properly validate session IDs.gitea · gitea · CWE-384 | Критическая9,8 | — | 3,0 % | 4 нояб. 2018 г. |
40В плане | CVE-2021-45327Эксплойта нет | Gitea before 1.11.2 is affected by Trusting HTTP Permission Methods on the Server Side when referencing the vulnerable admin or user API.gitea · gitea · CWE-436 | Критическая9,8 | — | 2,1 % | 8 февр. 2022 г. |
40В плане | CVE-2019-11576Эксплойта нет | Gitea before 1.8.0 allows 1FA for user accounts that have completed 2FA enrollment.gitea · gitea · CWE-287 | Критическая9,8 | — | 1,8 % | 27 апр. 2019 г. |
40В плане | CVE-2020-28991Эксплойта нет | Gitea 0.9.99 through 1.12.x before 1.12.6 does not prevent a git protocol path that specifies a TCP port number and also contains newlines (gitea · gitea | Критическая9,8 | — | 1,7 % | 23 нояб. 2020 г. |
39Наблюдать | CVE-2021-45330Эксплойта нет | An issue exsits in Gitea through 1.15.7, which could let a malicious user gain privileges due to client side cookies not being deleted and tgitea · gitea · CWE-459 | Критическая9,8 | — | 1,4 % | 9 февр. 2022 г. |
39Наблюдать | CVE-2021-45331Эксплойта нет | An Authentication Bypass vulnerability exists in Gitea before 1.5.0, which could let a malicious user gain privileges.gitea · gitea · CWE-287 | Критическая9,8 | — | 1,4 % | 9 февр. 2022 г. |
39Наблюдать | CVE-2022-42968Эксплойта нет | Gitea before 1.17.3 does not sanitize and escape refs in the git backend.gitea · gitea · CWE-88 | Критическая9,8 | — | 1,2 % | 16 окт. 2022 г. |
36Наблюдать | CVE-2026-20912Эксплойта нет | Gitea: Cross-Repository Authorization Bypass via Release Attachment Linking Leads to Private Attachment Disclosuregitea · gitea · CWE-284 | Критическая9,1 | — | 0,5 % | 22 янв. 2026 г. |
36Наблюдать | CVE-2026-20897Эксплойта нет | Gitea Git LFS Lock Deletion Broken Access Control (Cross-Repo IDOR)gitea · gitea · CWE-284 | Критическая9,1 | — | 0,5 % | 22 янв. 2026 г. |
36Наблюдать | CVE-2026-20750Эксплойта нет | Gitea Organization Projects Cross-Organization Authorization Bypass via Project ID (IDOR)gitea · gitea · CWE-284 | Критическая9,1 | — | 0,4 % | 22 янв. 2026 г. |
35Наблюдать | CVE-2018-15192Эксплойта нет | An SSRF vulnerability in webhooks in Gitea through 1.5.0-rc2 and Gogs through 0.11.53 allows remote attackers to access intranet services.gitea · gitea · CWE-918 | Высокая8,6 | — | 2,1 % | 7 авг. 2018 г. |
35Наблюдать | CVE-2021-45326Эксплойта нет | Cross Site Request Forgery (CSRF) vulnerability exists in Gitea before 1.5.2 via API routes.This can be dangerous especially with state altegitea · gitea · CWE-352 | Высокая8,8 | — | 0,6 % | 8 февр. 2022 г. |
31Наблюдать | CVE-2019-10330Эксплойта нет | Jenkins Gitea Plugin 1.1.1 and earlier did not implement trusted revisions, allowing attackers without commit access to the Git repo to changitea · gitea · CWE-862 | Высокая7,5 | — | 2,1 % | 31 мая 2019 г. |
31Наблюдать | CVE-2020-13246Эксплойта нет | An issue was discovered in Gitea through 1.11.5.gitea · gitea · CWE-667 | Высокая7,5 | — | 2,0 % | 20 мая 2020 г. |
31Наблюдать | CVE-2021-3382Эксплойта нет | Stack buffer overflow vulnerability in gitea 1.9.0 through 1.13.1 allows remote attackers to cause a denial of service (crash) via vectors rgitea · gitea · CWE-787 | Высокая7,5 | — | 1,8 % | 5 февр. 2021 г. |
30Наблюдать | CVE-2019-11228Эксплойта нет | repo/setting.go in Gitea before 1.7.6 and 1.8.x before 1.8-RC3 does not validate the form.MirrorAddress before calling SaveAddress.gitea · gitea · CWE-20 | Высокая7,5 | — | 1,3 % | 15 апр. 2019 г. |
30Наблюдать | CVE-2021-45325Эксплойта нет | Server Side Request Forgery (SSRF) vulneraility exists in Gitea before 1.7.0 using the OpenID URL.gitea · gitea · CWE-918 | Высокая7,5 | — | 1,0 % | 8 февр. 2022 г. |
30Наблюдать | CVE-2022-27313Эксплойта нет | An arbitrary file deletion vulnerability in Gitea v1.16.3 allows attackers to cause a Denial of Service (DoS) via deleting the configurationgitea · gitea | Высокая7,5 | — | 1,0 % | 3 мая 2022 г. |
30Наблюдать | CVE-2026-20736Эксплойта нет | Gitea Web Attachment Deletion: Cross-Repository Unauthorized Deletion via Missing Repo Ownership Checkgitea · gitea · CWE-284 | Высокая7,5 | — | 0,4 % | 22 янв. 2026 г. |
- CVE-2026-6000476На этой неделе
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 24 %gitea · gitea26 авг. 2026 г.
- CVE-2020-1414457В плане
The git hook feature in Gitea 1.1.0 through 1.12.5 might allow for authenticated remote code execution in customer environments where the do
ВысокаяCVSS 7,2Готовый эксплойтEPSS 95 %gitea · gitea16 окт. 2020 г.
- CVE-2022-3078156В плане
Gitea before 1.16.7 does not escape git fetch remote.
ВысокаяCVSS 7,5Готовый эксплойтEPSS 88 %gitea · gitea16 мая 2022 г.
- CVE-2019-1122951В плане
models/repo_mirror.go in Gitea before 1.7.6 and 1.8.x before 1.8-RC3 mishandles mirror repo URL settings, leading to remote code execution.
ВысокаяCVSS 8,8Proof of conceptEPSS 55 %gitea · gitea15 апр. 2019 г.
- CVE-2024-688650В плане
Inproper Sanitation of field leading to stored XSS
КритическаяCVSS 10,0Proof of conceptEPSS 33 %gitea · gitea open source git server6 авг. 2024 г.
- CVE-2022-105840В плане
Open Redirect on login in go-gitea/gitea
СредняяCVSS 6,1Proof of conceptEPSS 53 %gitea · gitea24 мар. 2022 г.
- CVE-2018-1892640В плане
Gitea before 1.5.4 allows remote code execution because it does not properly validate session IDs.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %gitea · gitea4 нояб. 2018 г.
- CVE-2021-4532740В плане
Gitea before 1.11.2 is affected by Trusting HTTP Permission Methods on the Server Side when referencing the vulnerable admin or user API.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %gitea · gitea8 февр. 2022 г.
- CVE-2019-1157640В плане
Gitea before 1.8.0 allows 1FA for user accounts that have completed 2FA enrollment.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %gitea · gitea27 апр. 2019 г.
- CVE-2020-2899140В плане
Gitea 0.9.99 through 1.12.x before 1.12.6 does not prevent a git protocol path that specifies a TCP port number and also contains newlines (
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %gitea · gitea23 нояб. 2020 г.
- CVE-2021-4533039Наблюдать
An issue exsits in Gitea through 1.15.7, which could let a malicious user gain privileges due to client side cookies not being deleted and t
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %gitea · gitea9 февр. 2022 г.
- CVE-2021-4533139Наблюдать
An Authentication Bypass vulnerability exists in Gitea before 1.5.0, which could let a malicious user gain privileges.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %gitea · gitea9 февр. 2022 г.
- CVE-2022-4296839Наблюдать
Gitea before 1.17.3 does not sanitize and escape refs in the git backend.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %gitea · gitea16 окт. 2022 г.
- CVE-2026-2091236Наблюдать
Gitea: Cross-Repository Authorization Bypass via Release Attachment Linking Leads to Private Attachment Disclosure
КритическаяCVSS 9,1Эксплойта нетEPSS 0 %gitea · gitea22 янв. 2026 г.
- CVE-2026-2089736Наблюдать
Gitea Git LFS Lock Deletion Broken Access Control (Cross-Repo IDOR)
КритическаяCVSS 9,1Эксплойта нетEPSS 0 %gitea · gitea22 янв. 2026 г.
- CVE-2026-2075036Наблюдать
Gitea Organization Projects Cross-Organization Authorization Bypass via Project ID (IDOR)
КритическаяCVSS 9,1Эксплойта нетEPSS 0 %gitea · gitea22 янв. 2026 г.
- CVE-2018-1519235Наблюдать
An SSRF vulnerability in webhooks in Gitea through 1.5.0-rc2 and Gogs through 0.11.53 allows remote attackers to access intranet services.
ВысокаяCVSS 8,6Эксплойта нетEPSS 2 %gitea · gitea7 авг. 2018 г.
- CVE-2021-4532635Наблюдать
Cross Site Request Forgery (CSRF) vulnerability exists in Gitea before 1.5.2 via API routes.This can be dangerous especially with state alte
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %gitea · gitea8 февр. 2022 г.
- CVE-2019-1033031Наблюдать
Jenkins Gitea Plugin 1.1.1 and earlier did not implement trusted revisions, allowing attackers without commit access to the Git repo to chan
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %gitea · gitea31 мая 2019 г.
- CVE-2020-1324631Наблюдать
An issue was discovered in Gitea through 1.11.5.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %gitea · gitea20 мая 2020 г.
- CVE-2021-338231Наблюдать
Stack buffer overflow vulnerability in gitea 1.9.0 through 1.13.1 allows remote attackers to cause a denial of service (crash) via vectors r
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %gitea · gitea5 февр. 2021 г.
- CVE-2019-1122830Наблюдать
repo/setting.go in Gitea before 1.7.6 and 1.8.x before 1.8-RC3 does not validate the form.MirrorAddress before calling SaveAddress.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %gitea · gitea15 апр. 2019 г.
- CVE-2021-4532530Наблюдать
Server Side Request Forgery (SSRF) vulneraility exists in Gitea before 1.7.0 using the OpenID URL.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %gitea · gitea8 февр. 2022 г.
- CVE-2022-2731330Наблюдать
An arbitrary file deletion vulnerability in Gitea v1.16.3 allows attackers to cause a Denial of Service (DoS) via deleting the configuration
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %gitea · gitea3 мая 2022 г.
- CVE-2026-2073630Наблюдать
Gitea Web Attachment Deletion: Cross-Repository Unauthorized Deletion via Missing Repo Ownership Check
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %gitea · gitea22 янв. 2026 г.