Description
Gitea version 1.6.2 and earlier contains a Incorrect Access Control vulnerability in Delete/Edit file functionallity that can result in the attacker deleting files outside the repository he/she has access to. This attack appears to be exploitable via the attacker must get write access to "any" repository including self-created ones.. This vulnerability appears to have been fixed in 1.6.3, 1.7.0-rc2.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-4323 | Gitea version 1.6.2 and earlier contains a Incorrect Access Control vulnerability in Delete/Edit file functionallity that can result in the attacker deleting files outside the repository he/she has access to. This attack appears to be exploitable via the attacker must get write access to "any" repository including self-created ones.. This vulnerability appears to have been fixed in 1.6.3, 1.7.0-rc2. |
Github GHSA |
GHSA-j99q-rwp6-498g | Gitea Arbitrary File Delete Vulnerability |
References
| Link | Providers |
|---|---|
| https://github.com/go-gitea/gitea/pull/5631 |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T03:00:19.397Z
Reserved: 2019-01-04T00:00:00.000Z
Link: CVE-2019-1000002
No data.
Status : Modified
Published: 2019-02-04T21:29:00.690
Modified: 2024-11-21T04:17:39.003
Link: CVE-2019-1000002
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA