V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2021-45327
DEB
Critical

Gitea before 1.11.2 is affected by Trusting HTTP Permission Methods on the Server Side when referencing the vulnerable admin or user API. w…

CVSS
9.8
Critical
EPSS
0.02
p78
Published
2021-01-01
Updated
2021-01-01
Description

Gitea before 1.11.2 is affected by Trusting HTTP Permission Methods on the Server Side when referencing the vulnerable admin or user API. which could let a remote malisious user execute arbitrary code.

Tags · CWE
Pre-auth
CWE-436
CAPEC-34
CAPEC-105
CAPEC-273
Affected products
Gitea < 1.11.2
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Timeline
2021-01-01
Published
2021-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.021 · p78
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
giteaTracked
golang-code.gitea-gitTracked
golang-code.gitea-gitTracked
golang-code.gitea-gitTracked
golang-code.gitea-gitTracked
golang-code.gitea-gitTracked
golang-code.gitea-gitTracked
golang-code.gitea-sdkTracked
golang-code.gitea-sdkTracked
golang-code.gitea-sdkTracked
golang-code.gitea-sdkTracked
golang-code.gitea-sdkTracked
golang-code.gitea-sdkTracked
gitea*Tracked
Source databases
DEB
CVE
UBU
Related vulnerabilities