CVE-2021-45327: Critical severity gitea vulnerability
Gitea before 1.11.2 is affected by Trusting HTTP Permission Methods on the Server Side when referencing the vulnerable admin or user API. which could let a remote malisious user execute arbitrary code.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-45327?
CVE-2021-45327 is a vulnerability in Gitea before version 1.11.2 that allows a remote malicious user to execute arbitrary code by exploiting the trust of HTTP permission methods on the server side when referencing the vulnerable admin or user API.
What software is affected by CVE-2021-45327?
Gitea versions before 1.11.2 are affected by CVE-2021-45327.
What is the severity of CVE-2021-45327?
CVE-2021-45327 has a severity rating of 9.8, which is considered critical.
How can a remote malicious user exploit CVE-2021-45327?
A remote malicious user can exploit CVE-2021-45327 by referencing the vulnerable admin or user API and exploiting the trust of HTTP permission methods on the server side.
Is there a fix for CVE-2021-45327?
Yes, upgrading Gitea to version 1.11.2 or later will fix the CVE-2021-45327 vulnerability.