CVE-2021-45330

CRITICAL

Gitea <1.15.7 - Privilege Escalation

Title source: llm
STIX 2.1

Description

An issue exsits in Gitea through 1.15.7, which could let a malicious user gain privileges due to client side cookies not being deleted and the session remains valid on the server side for reuse.

Scores

CVSS v3 9.8
EPSS 0.0113
EPSS Percentile 78.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-459
Status published
Products (2)
code.gitea.io/gitea 0 - 1.6.0Go
gitea/gitea < 1.15.7
Published Feb 09, 2022
Tracked Since Feb 18, 2026