VDB
EN
CRITICAL

GHSA-rgv6-xp99-6mgj

Gitea Remember-Me Token Theft Not Invalidating Attacker Session

빠른 조치

GHSA-rgv6-xp99-6mgj — code.gitea.io/gitea: 아래 명령으로 수정 버전으로 올리세요.

go get code.gitea.io/gitea@v1.27.0

상세

The vulnerability is in the Remember-Me (gitea_incredible) token validation logic, specifically when handling a compromised token (hash mismatch).

The vulnerable function is this one:

https://github.com/go-gitea/gitea/blob/689ace1ce28fd74244b8aa335d9928cdbf6b22f9/services/auth/auth_token.go#L33-L64

### Affected Endpoint POST `/user/login` (and any endpoint triggering `autoSignIn` via the Remember-Me cookie).

### Description Gitea implements Remember-Me cookies using a split token design (ID:Hash), [citing the Paragonie secure remember-me guide](https://github.com/go-gitea/gitea/blob/689ace1ce28fd74244b8aa335d9928cdbf6b22f9/services/auth/auth_token.go#L21). When a token is used, its Hash is rotated, but the ID remains the same.

If an attacker steals a user's Remember-Me token and uses it to authenticate, the attacker is issued a new rotated token (same ID, new Hash). When the legitimate user later attempts to use their original token, Gitea correctly detects a hash mismatch for the given ID.

According to the referenced Paragonie specification, this indicates a compromised token, and ALL active remember-me sessions for that user MUST be invalidated. However, Gitea's `CheckAuthToken` function simply returns `ErrAuthTokenInvalidHash`. The calling code (`autoSignIn`) catches this error and deletes the victim's local cookie via `ctx.DeleteSiteCookie`, but fails to delete the compromised token from the database.

As a result, the attacker's active session is never invalidated, and the attacker maintains persistent, indefinite access to the victim's account, entirely defeating the purpose of the split-token security design.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

Go / code.gitea.io/gitea
최초 영향 버전: 0 수정 버전: 1.27.0
수정 go get code.gitea.io/gitea@v1.27.0

참고