CVE-2022-1058: Open Redirect on login in go-gitea/gitea
Published Mar 24, 2022
·Updated
Open Redirect on login in GitHub repository go-gitea/gitea prior to 1.16.5.
Affected Software
2 affected componentsFixes available
go/code.gitea.io/gitea<1.16.5
1.16.5
Gitea Gitea<1.16.5
Remediation
Event History
Mar 24, 2022
CVE Published
via MITRE·02:15 PM
Data Sourced
via MITRE·02:15 PM
DescriptionSeverityWeakness
Mar 25, 2022
Advisory Published
via GitHub·12:00 AM
Frequently Asked Questions
1
What is CVE-2022-1058?
CVE-2022-1058 is an open redirect vulnerability on the login page in the GitHub repository go-gitea/gitea prior to version 1.16.5.
2
How severe is CVE-2022-1058?
CVE-2022-1058 has a severity score of 6.1 (High).
3
How does CVE-2022-1058 affect Gitea?
CVE-2022-1058 affects Gitea versions prior to 1.16.5.
4
How can I fix CVE-2022-1058?
To fix CVE-2022-1058, update your Gitea installation to version 1.16.5 or later.
5
Where can I find more information about CVE-2022-1058?
You can find more information about CVE-2022-1058 in the GitHub commit and the huntr.dev bounty links: [GitHub Commit](https://github.com/go-gitea/gitea/commit/e3d8e92bdc67562783de9a76b5b7842b68daeb48), [huntr.dev Bounty](https://huntr.dev/bounties/4fb42144-ac70-4f76-a5e1-ef6b5e55dc0d).