CVE Vulnerabilities

CVE-2021-45327

Interpretation Conflict

Published: Feb 08, 2022 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Gitea before 1.11.2 is affected by Trusting HTTP Permission Methods on the Server Side when referencing the vulnerable admin or user API. which could let a remote malisious user execute arbitrary code.

Weakness

Product A handles inputs or steps differently than Product B, which causes A to perform incorrect actions based on its perception of B’s state.

Affected Software

NameVendorStart VersionEnd Version
GiteaGitea*1.11.2 (excluding)
Golang-code.gitea-gitUbuntubionic*
Golang-code.gitea-gitUbuntufocal*
Golang-code.gitea-gitUbuntuimpish*
Golang-code.gitea-gitUbuntukinetic*
Golang-code.gitea-gitUbuntutrusty*
Golang-code.gitea-gitUbuntuxenial*
Golang-code.gitea-sdkUbuntubionic*
Golang-code.gitea-sdkUbuntufocal*
Golang-code.gitea-sdkUbuntuimpish*
Golang-code.gitea-sdkUbuntukinetic*
Golang-code.gitea-sdkUbuntutrusty*
Golang-code.gitea-sdkUbuntuxenial*

References