Bug 2135739 (CVE-2022-42968) - CVE-2022-42968 gitea: Sanitize and Escape refs in git backend
Summary: CVE-2022-42968 gitea: Sanitize and Escape refs in git backend
Keywords:
Status: NEW
Alias: CVE-2022-42968
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Nobody
QA Contact:
URL:
Whiteboard:
Depends On: 2135855
Blocks: 2135210
TreeView+ depends on / blocked
 
Reported: 2022-10-18 10:21 UTC by Avinash Hanwate
Modified: 2023-07-07 08:34 UTC (History)
12 users (show)

Fixed In Version: Gitea 1.17.3
Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in Gitea. The self-hosted Git service does not sanitize and escape refs in the git backend. This issue could allow an attacker to craft arguments for the git commands, which will be mishandled.
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Avinash Hanwate 2022-10-18 10:21:40 UTC
Gitea before 1.17.3 does not sanitize and escape refs in the git backend. Arguments to git commands are mishandled.

https://github.com/go-gitea/gitea/pull/21463
https://github.com/go-gitea/gitea/releases/tag/v1.17.3


Note You need to log in before you can comment on or make changes to this bug.