Remote Code Execution Vulnerability in Gitea Software
CVE-2020-14144
Key Information:
Badges
What is CVE-2020-14144?
The Git hook feature in Gitea versions 1.1.0 through 1.12.5 may lead to remote code execution in environments where the feature is misconfigured. The documentation is noted to lack clarity regarding the risks associated with enabling Git hooks, which could allow users with certain privileges to execute arbitrary code on the server. While the vendor asserts this behavior is intended functionality, it highlights the importance of proper configuration and user awareness in security practices.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
EPSS Score
93% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved

