Authentication Bypass Vulnerability in Gitea by Gitea
CVE-2021-45331
9.8CRITICAL
What is CVE-2021-45331?
An authentication bypass vulnerability exists in Gitea versions prior to 1.5.0. This flaw allows a malicious actor to exploit the two-factor authentication (2FA) mechanism, enabling them to submit the Time-based One-Time Password (TOTP) code multiple times without proper validation. As a result, potentially unauthorized users may gain elevated privileges, compromising the security of the affected installations.
