Skip to content

x/vulndb: potential Go vuln in github.com/go-gitea/gitea: CVE-2022-42968 #1065

Closed
@GoVulnBot

Description

@GoVulnBot

CVE-2022-42968 references github.com/go-gitea/gitea, which may be a Go module.

Description:
Gitea before 1.17.3 does not sanitize and escape refs in the git backend. Arguments to git commands are mishandled.

References:

See doc/triage.md for instructions on how to triage this report.

modules:
  - module: github.com/go-gitea/gitea
    packages:
      - package: n/a
description: |
    Gitea before 1.17.3 does not sanitize and escape refs in the git backend. Arguments to git commands are mishandled.
cves:
  - CVE-2022-42968
references:
  - fix: https://github.com/go-gitea/gitea/pull/21463
  - web: https://github.com/go-gitea/gitea/releases/tag/v1.17.3

Metadata

Metadata

Assignees

No one assigned

    Labels

    excluded: EFFECTIVELY_PRIVATEThis vulnerability exists in a package can be imported, but isn't meant to be outside that module.

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions