blob: c7df4fa4e4396fef97ecb1185cc835f0850d4d58 [file] [log] [blame]
id: GO-2022-0450
modules:
- module: code.gitea.io/gitea
versions:
- fixed: 1.16.7
vulnerable_at: 1.16.6
summary: Shell command injection in gitea in code.gitea.io/gitea
cves:
- CVE-2022-30781
ghsas:
- GHSA-p5f9-c9j9-g8qx
references:
- advisory: https://github.com/advisories/GHSA-p5f9-c9j9-g8qx
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2022-30781
- web: http://packetstormsecurity.com/files/168400/Gitea-1.16.6-Remote-Code-Execution.html
- web: http://packetstormsecurity.com/files/169928/Gitea-Git-Fetch-Remote-Code-Execution.html
- web: https://blog.gitea.io/2022/05/gitea-1.16.7-is-released
- web: https://github.com/go-gitea/gitea/pull/19487
- web: https://github.com/go-gitea/gitea/pull/19490
source:
id: GHSA-p5f9-c9j9-g8qx
created: 2024-08-20T13:57:28.338772-04:00
review_status: UNREVIEWED
unexcluded: EFFECTIVELY_PRIVATE