HIGH8.2
GHSA-263q-5cv3-xq9g
Gitea allows attackers to add attachments with forbidden file extensions
Details
Gitea before 1.23.0 allows attackers to add attachments with forbidden file extensions by editing an attachment name via an attachment API.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/code.gitea.io/gitea
Introduced in:
0No fixed version published yet for code.gitea.io/gitea (go modules). Pin to a known-safe version or switch to an alternative.