CVE-2020-28991: Critical severity gitea vulnerability
Published Nov 24, 2020
·Updated
Gitea 0.9.99 through 1.12.x before 1.12.6 does not prevent a git protocol path that specifies a TCP port number and also contains newlines (with URL encoding) in ParseRemoteAddr in modules/auth/repoform.go.
Affected Software
2 affected componentsFixes available
go/github.com/go-gitea/gitea>=0.9.99<1.12.6
1.12.6
Gitea Gitea>=0.9.99<1.12.6
Remediation
Patch Available
Event History
Nov 24, 2020
CVE Published
via MITRE·12:29 AM
Data Sourced
via MITRE·12:29 AM
Description
Apr 24, 2024
Advisory Published
via GitHub·08:56 PM
Frequently Asked Questions
1
What is the severity of CVE-2020-28991?
The severity of CVE-2020-28991 is critical with a value of 9.8.
2
Which versions of Gitea are affected by CVE-2020-28991?
Gitea versions 0.9.99 through 1.12.x before 1.12.6 are affected by CVE-2020-28991.
3
How does CVE-2020-28991 impact Gitea?
CVE-2020-28991 allows an attacker to specify a TCP port number and include newlines in the git protocol path.
4
Is there a fix for CVE-2020-28991?
Yes, the fix for CVE-2020-28991 is included in Gitea version 1.12.6.
5
Where can I find more information about CVE-2020-28991?
You can find more information about CVE-2020-28991 in the following references: [1] [2].