CVE-2022-42968: Critical severity Gitea Gitea vulnerability
Gitea before 1.17.3 does not sanitize and escape refs in the git backend. Arguments to git commands are mishandled.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-42968?
CVE-2022-42968 is a vulnerability in Gitea before version 1.17.3 that allows for the mishandling of arguments to git commands.
How does CVE-2022-42968 affect Gitea?
CVE-2022-42968 affects Gitea before version 1.17.3 by not properly sanitizing and escaping refs in the git backend, leading to mishandling of git command arguments.
What is the severity of CVE-2022-42968?
CVE-2022-42968 has a severity rating of critical with a CVSS score of 9.8.
How can I fix the CVE-2022-42968 vulnerability?
To fix the CVE-2022-42968 vulnerability, upgrade Gitea to version 1.17.3 or later.
Are there any references for CVE-2022-42968?
Yes, you can find references for CVE-2022-42968 at the following links: [link1](https://github.com/go-gitea/gitea/pull/21463), [link2](https://github.com/go-gitea/gitea/releases/tag/v1.17.3), [link3](https://security.gentoo.org/glsa/202210-14)