CVE-2019-11229 describes a remote code execution (RCE) vulnerability in Gitea versions prior to 1.7.6 and 1.8.x before 1.8-RC3, stemming from improper handling of mirror repository URL settings. This vulnerability carries a CVSS score of 8.8 (High), indicating that an authenticated attacker can achieve full compromise of confidentiality, integrity, and availability over a network with low attack complexity. While not listed on the KEV catalog, an exploit (EDB-49383) is publicly available, though there is no evidence of active exploitation, Metasploit modules, or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.7.6CPE matchmatch criteria | cpe:2.3:a:gitea:gitea:*:*:*:*:*:*:*:* | ||
1.8.0CPE matchmatch criteria | cpe:2.3:a:gitea:gitea:1.8.0:rc1:*:*:*:*:*:* | ||
1.8.0CPE matchmatch criteria | cpe:2.3:a:gitea:gitea:1.8.0:rc2:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Gitea Remote Code Execution
Feb 15, 2022Vulnerable upstream Library
Vulnerable upstream Library
Vulnerable upstream Library
Vulnerable upstream Library
Vulnerable upstream Library