Record summary

CVE-2021-45328 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

Gitea before 1.4.3 is affected by URL Redirection to Untrusted Site ('Open Redirect') via internal URLs.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

github.com/go-gitea/gitea

Browse Go / github.com/go-gitea/gitea
GitHub AdvisoryBefore 1.4.3 · Fixed in 1.4.3affected

Nuclei templates

1
ProjectDiscoveryMEDIUMGitea < 1.4.3 - Open RedirectCVSS 6.1

Gitea before version 1.4.3 is affected by URL Redirection to Untrusted Site ('Open Redirect') via internal URLs. The vulnerability exists in the redirect_to parameter used on the login page (/user/login). Due to improper validation of the redirect URL, an attacker can craft a malicious link that redirects authenticated users to an arbitrary external website after login.

Impact

An attacker can exploit this vulnerability to redirect users to malicious websites, leading to phishing attacks or the theft of sensitive information.

Remediation

Upgrade Gitea to version 1.4.3 or later to fix the open redirect vulnerability.

WeaknessesCWE-601
Authorsritikchaddha
Template tagscvecve2021redirectgitea
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:gitea:gitea:*:*:*:*:*:*:*:*
Shodan: title:"Gitea"
Shodan: http.html:"powered by gitea version"
Shodan: http.title:"gitea"
Shodan: cpe:"cpe:2.3:a:gitea:gitea"
FOFA: body="powered by gitea version"
FOFA: title="gitea"
Google: intitle:"gitea"

Source: ProjectDiscovery

References

4