-
-
Notifications
You must be signed in to change notification settings - Fork 6.2k
Closed
Labels
topic/securitySomething leaks user information or is otherwise vulnerable. Should be fixed!Something leaks user information or is otherwise vulnerable. Should be fixed!
Description
The vulnerability impacting Gogs also impacts gitea
gogs/gogs#5558
-
Gitea version (or commit ref): 8dc09ed
-
Can you reproduce the bug at https://try.gitea.io:
- Yes
Description
By using upload file with a malicious filename, an attacker is able to become any users and then gain code execution using hooks.
Gogs already worked on the issue in their develop branch
Screenshots
Me logged in as user_id 1
renothing and HenrikBengtsson
Metadata
Metadata
Assignees
Labels
topic/securitySomething leaks user information or is otherwise vulnerable. Should be fixed!Something leaks user information or is otherwise vulnerable. Should be fixed!
