CVE-2019-1000002: Medium severity gitea vulnerability
Gitea version 1.6.2 and earlier contains a Incorrect Access Control vulnerability in Delete/Edit file functionallity that can result in the attacker deleting files outside the repository he/she has access to. This attack appears to be exploitable via the attacker must get write access to "any" repository including self-created ones. This vulnerability appears to have been fixed in 1.6.3, 1.7.0-rc2.
Other sources
Gitea version 1.6.2 and earlier contains a Incorrect Access Control vulnerability in Delete/Edit file functionallity that can result in the attacker deleting files outside the repository he/she has access to. This attack appears to be exploitable via the attacker must get write access to "any" repository including self-created ones.. This vulnerability appears to have been fixed in 1.6.3, 1.7.0-rc2.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-1000002?
CVE-2019-1000002 is a vulnerability in Gitea version 1.6.2 and earlier that allows an attacker to delete files outside the repository they have access to.
What is the severity of CVE-2019-1000002?
The severity of CVE-2019-1000002 is medium with a CVSS score of 6.5.
How can an attacker exploit CVE-2019-1000002?
An attacker can exploit CVE-2019-1000002 by gaining write access to any repositories and then using the Delete/Edit file functionality to delete files outside their repository.
Which version of Gitea is affected by CVE-2019-1000002?
Versions 1.6.2 and earlier of Gitea are affected by CVE-2019-1000002.
Is there a fix for CVE-2019-1000002?
Yes, a fix for CVE-2019-1000002 is available. It is recommended to upgrade to a version of Gitea that is not affected by this vulnerability.