CVE-2020-13246: High severity gitea vulnerability
An issue was discovered in Gitea through 1.11.5. An attacker can trigger a deadlock by initiating a transfer of a repository's ownership from one organization to another.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-13246?
CVE-2020-13246 is a vulnerability discovered in Gitea through version 1.11.5 that allows an attacker to trigger a deadlock by initiating a transfer of a repository's ownership from one organization to another.
What is the severity of CVE-2020-13246?
CVE-2020-13246 has a severity rating of 7.5 (high).
How can an attacker exploit CVE-2020-13246?
An attacker can exploit CVE-2020-13246 by initiating a transfer of a repository's ownership from one organization to another.
Is there a fix available for CVE-2020-13246?
Yes, a fix is available for CVE-2020-13246. Upgrade Gitea to a version beyond 1.11.5.
Where can I find more information about CVE-2020-13246?
More information about CVE-2020-13246 can be found in the following references: - [GitHub issue #10549](https://github.com/go-gitea/gitea/issues/10549) - [GitHub pull request #11438](https://github.com/go-gitea/gitea/pull/11438) - [YouTube video](https://www.youtube.com/watch?v=DmVgADSVS88)