CVE-2021-29134: Path Traversal
Published Mar 15, 2022
·Updated
The avatar middleware in Gitea before 1.13.6 allows Directory Traversal via a crafted URL.
Affected Software
1 affected component
Gitea Gitea<1.13.6
Remediation
Patch Available
Patch Available
Event History
Mar 15, 2022
CVE Published
via MITRE·08:30 PM
Data Sourced
via MITRE·08:30 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-29134.
2
What is the severity of CVE-2021-29134?
The severity of CVE-2021-29134 is medium.
3
How does CVE-2021-29134 affect Gitea?
CVE-2021-29134 affects Gitea versions up to and including 1.13.6.
4
What is the CWE for CVE-2021-29134?
The CWE for CVE-2021-29134 is CWE-22.
5
How can I fix CVE-2021-29134?
To fix CVE-2021-29134, update Gitea to version 1.13.6 or later.