First published: Wed May 20 2020(Updated: )
An issue was discovered in Gitea through 1.11.5. An attacker can trigger a deadlock by initiating a transfer of a repository's ownership from one organization to another.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Gitea Gitea | <=1.11.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-13246 is a vulnerability discovered in Gitea through version 1.11.5 that allows an attacker to trigger a deadlock by initiating a transfer of a repository's ownership from one organization to another.
CVE-2020-13246 has a severity rating of 7.5 (high).
An attacker can exploit CVE-2020-13246 by initiating a transfer of a repository's ownership from one organization to another.
Yes, a fix is available for CVE-2020-13246. Upgrade Gitea to a version beyond 1.11.5.
More information about CVE-2020-13246 can be found in the following references: - [GitHub issue #10549](https://github.com/go-gitea/gitea/issues/10549) - [GitHub pull request #11438](https://github.com/go-gitea/gitea/pull/11438) - [YouTube video](https://www.youtube.com/watch?v=DmVgADSVS88)