models/repo_mirror.go in Gitea before 1.7.6 and 1.8.x before 1.8-RC3 mishandles mirror repo URL settings, leading to remote code execution.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Gitea | Gitea | * | 1.7.6 (excluding) |
| Gitea | Gitea | 1.8.0-rc1 (including) | 1.8.0-rc1 (including) |
| Gitea | Gitea | 1.8.0-rc2 (including) | 1.8.0-rc2 (including) |