-
-
Notifications
You must be signed in to change notification settings - Fork 5.5k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Gitea grants 0750 rights to uploaded avatars #22161
Labels
Comments
zeripath
added a commit
to zeripath/gitea
that referenced
this issue
Dec 18, 2022
The PR go-gitea#21198 introduced a probable security vulnerability which resulted in making all storage files be marked as executable. This PR ensures that these are forcibly marked as non-executable. Fix go-gitea#22161 Signed-off-by: Andrew Thornton <art27@cantab.net>
zeripath
added a commit
to zeripath/gitea
that referenced
this issue
Dec 18, 2022
Backport go-gitea#22162 The PR go-gitea#21198 introduced a probable security vulnerability which resulted in making all storage files be marked as executable. This PR ensures that these are forcibly marked as non-executable. Fix go-gitea#22161 Signed-off-by: Andrew Thornton <art27@cantab.net>
🤦 |
@zeripath thanks. fixed. |
@Izorkin do you mean the pr fixes the problem? It's probably better to comment on the PR directly to indicate that you think it's correct. |
Yes, fixed my problem. |
lafriks
pushed a commit
that referenced
this issue
Dec 18, 2022
Backport #22162 The PR #21198 introduced a probable security vulnerability which resulted in making all storage files be marked as executable. This PR ensures that these are forcibly marked as non-executable. Fix #22161 Signed-off-by: Andrew Thornton <art27@cantab.net> Signed-off-by: Andrew Thornton <art27@cantab.net>
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Description
Gitea grants 0750 rights to uploaded avatars
Required grants -
06500640.Gitea Version
1.18-dev
Can you reproduce the bug on the Gitea demo site?
Yes
Log Gist
No response
Screenshots
No response
Git Version
No response
Operating System
NixOS
How are you running Gitea?
Using gitea module in OS NixOS.
Database
None
The text was updated successfully, but these errors were encountered: