CVE-2022-38795: Medium severity gitea vulnerability
Published Aug 7, 2023
·Updated
In Gitea through 1.17.1, repo cloning can occur in the migration function.
Affected Software
2 affected componentsFixes available
go/code.gitea.io/gitea<1.17.2
1.17.2
Gitea Gitea<=1.17.1
Remediation
Patch Available
Patch Available
Event History
Aug 7, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Advisory Published
03:30 PM
Frequently Asked Questions
1
What is CVE-2022-38795?
CVE-2022-38795 is a vulnerability in Gitea through 1.17.1 that allows repo cloning to occur in the migration function.
2
How can repo cloning occur in the migration function due to CVE-2022-38795?
In Gitea through version 1.17.1, the migration function allows repo cloning to take place, which can be exploited.
3
What is the severity of CVE-2022-38795?
CVE-2022-38795 has a severity rating of medium, with a CVSS score of 6.5.
4
What is the affected software for CVE-2022-38795?
The affected software for CVE-2022-38795 includes Gitea versions up to and including 1.17.1.
5
How can I fix CVE-2022-38795?
To fix CVE-2022-38795, update Gitea to version 1.17.2 or later.