CVE-2021-45330: Critical severity gitea vulnerability
Published Feb 9, 2022
·Updated
An issue exsits in Gitea through 1.15.7, which could let a malicious user gain privileges due to client side cookies not being deleted and the session remains valid on the server side for reuse.
Affected Software
1 affected component
Gitea Gitea<=1.15.7
Event History
Feb 9, 2022
CVE Published
via MITRE·05:16 PM
Data Sourced
via MITRE·05:16 PM
Description
Frequently Asked Questions
1
What is CVE-2021-45330?
CVE-2021-45330 is a vulnerability that exists in Gitea through version 1.15.7, allowing a malicious user to gain privileges.
2
How severe is CVE-2021-45330?
CVE-2021-45330 is classified as a critical vulnerability with a severity score of 9.8 out of 10.
3
How does CVE-2021-45330 work?
CVE-2021-45330 allows a malicious user to exploit client-side cookies that are not deleted, enabling them to reuse a valid session on the server side and gain privileges.
4
Which software versions are affected by CVE-2021-45330?
Gitea versions up to and including 1.15.7 are affected by CVE-2021-45330.
5
Is there a fix for CVE-2021-45330?
Yes, updating Gitea to a version beyond 1.15.7 will resolve the vulnerability.