Description
An issue exsits in Gitea through 1.15.7, which could let a malicious user gain privileges due to client side cookies not being deleted and the session remains valid on the server side for reuse.
Scores
CVSS v3
9.8
EPSS
0.0113
EPSS Percentile
78.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-459
Status
published
Products (2)
code.gitea.io/gitea
0 - 1.6.0Go
gitea/gitea
< 1.15.7
Published
Feb 09, 2022
Tracked Since
Feb 18, 2026