VDB
Sign up
LOW3.0

GHSA-cf6v-9j57-v6r6

code.gitea.io/gitea Open Redirect vulnerability

Quick fix

GHSA-cf6v-9j57-v6r6 — code.gitea.io/gitea: upgrade to the fixed version with the command below.

go get code.gitea.io/gitea@v1.19.4

Details

Open Redirect in GitHub repository go-gitea/gitea prior to 1.19.4. This is most likely a post-auth redirect plus it is a POST based request scenario, so less likely that can be exploited or chained with other bugs that can cause phishing or credential theft.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/code.gitea.io/gitea
Introduced in: 0Fixed in: 1.19.4
Fixgo get code.gitea.io/gitea@v1.19.4

References