First published: Wed Feb 09 2022(Updated: )
An issue exsits in Gitea through 1.15.7, which could let a malicious user gain privileges due to client side cookies not being deleted and the session remains valid on the server side for reuse.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Gitea Gitea | <=1.15.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-45330 is a vulnerability that exists in Gitea through version 1.15.7, allowing a malicious user to gain privileges.
CVE-2021-45330 is classified as a critical vulnerability with a severity score of 9.8 out of 10.
CVE-2021-45330 allows a malicious user to exploit client-side cookies that are not deleted, enabling them to reuse a valid session on the server side and gain privileges.
Gitea versions up to and including 1.15.7 are affected by CVE-2021-45330.
Yes, updating Gitea to a version beyond 1.15.7 will resolve the vulnerability.