CVE-2019-11229: Code Injection
Published Apr 13, 2019
·Updated
models/repomirror.go in Gitea before 1.7.6 and 1.8.x before 1.8-RC3 mishandles mirror repo URL settings, leading to remote code execution.
Affected Software
4 affected componentsFixes available
go/github.com/go-gitea/gitea<1.7.6
1.7.6
Gitea Gitea<1.7.6
Gitea Gitea=1.8.0-rc1
Gitea Gitea=1.8.0-rc2
Event History
Apr 13, 2019
CVE Published
via MITRE·03:07 PM
Data Sourced
via MITRE·03:07 PM
Description
Feb 15, 2022
Advisory Published
01:57 AM
Frequently Asked Questions
1
What is CVE-2019-11229?
CVE-2019-11229 is a vulnerability in Gitea versions before 1.7.6 and 1.8.x before 1.8-RC3 that mishandles mirror repo URL settings, allowing remote code execution.
2
How severe is CVE-2019-11229?
CVE-2019-11229 has a severity rating of high, with a score of 7.5.
3
What software is affected by CVE-2019-11229?
Gitea versions before 1.7.6 and 1.8.x before 1.8-RC3 are affected by CVE-2019-11229.
4
How can I fix CVE-2019-11229?
To fix CVE-2019-11229, you should update Gitea to version 1.7.6 or later.
5
What is the Common Weakness Enumeration (CWE) ID for CVE-2019-11229?
The CWE ID for CVE-2019-11229 is CWE-94.