CVE-2022-0905
unknown
CVSS v3
—
CVSS v2
—
VIR risk
—
Description
Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Predictions
Exploit likelihood
30%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| Go | code.gitea.io/gitea | <1.16.4 | 1.16.4 |
References
- https://nvd.nist.gov/vuln/detail/CVE-2022-0905
- https://github.com/go-gitea/gitea/commit/1314f38b59748397b3429fb9bc9f9d6bac85d2f2
- https://github.com/go-gitea/gitea/commit/3e5c844a7758fa29126d201f4f98bf21bca6d314
- https://github.com/go-gitea/gitea
- https://huntr.dev/bounties/8d221f92-b2b1-4878-bc31-66ff272e5ceb
- https://github.com/advisories/GHSA-jr9c-h74f-2v28
Verify integrity in audit chain (admin only). AS-IS.