CVE-2022-0905: Missing Authorization in go-gitea/gitea
Published Mar 10, 2022
·Updated
Missing Authorization in GitHub repository go-gitea/gitea prior to 1.16.4.
Affected Software
1 affected component
Gitea Gitea<1.16.4
Remediation
Event History
Mar 10, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-0905?
CVE-2022-0905 is a vulnerability in the GitHub repository go-gitea/gitea prior to version 1.16.4 that allows unauthorized access.
2
How severe is CVE-2022-0905?
CVE-2022-0905 has a severity rating of 7.1 (high).
3
How does CVE-2022-0905 affect Gitea?
CVE-2022-0905 affects Gitea versions up to and excluding 1.16.4.
4
What is the Common Weakness Enumeration (CWE) for CVE-2022-0905?
The CWE for CVE-2022-0905 is CWE-862.
5
How can CVE-2022-0905 be fixed?
To fix CVE-2022-0905, it is recommended to upgrade Gitea to version 1.16.4 or later.