Cross Site Request Forgery Vulnerability in Gitea by Gitea
CVE-2021-45326

8.8HIGH

Key Information:

Vendor

Gitea

Status
Vendor
CVE Published:
8 February 2022

What is CVE-2021-45326?

A Cross Site Request Forgery (CSRF) vulnerability has been identified in Gitea prior to version 1.5.2, which affects API routes. This security issue poses a serious risk, particularly due to its potential to manipulate state-altering POST requests, enabling unauthorized actions without user consent. It is crucial for users of Gitea to apply the latest updates to mitigate these risks and enhance overall application security.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2021-45326 : Cross Site Request Forgery Vulnerability in Gitea by Gitea