github.com
https://github.com/go-gitea/gitea CVE-2022-1058
MEDIUMNuclei
Open Redirect on login in go-gitea/gitea
Record summary
CVE-2022-1058 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
Open Redirect on login in GitHub repository go-gitea/gitea prior to 1.16.5.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
go-gitea/giteaBrowse go-gitea / go-gitea/gitea | CVE List | Before 1.16.5 | affected |
code.gitea.io/giteaBrowse Go / code.gitea.io/gitea | GitHub Advisory | Before 1.16.5 · Fixed in 1.16.5 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMGitea <1.16.5 - Open RedirectCVSS 6.1
Gitea before 1.16.5 is susceptible to open redirect via GitHub repository go-gitea/gitea. An attacker can redirect a user to a malicious site and potentially obtain sensitive information, modify data, and/or execute unauthorized operations.
Impact
An attacker can exploit this vulnerability to redirect users to malicious websites, leading to phishing attacks or the theft of sensitive information.
Remediation
Upgrade Gitea to version 1.16.5 or later to fix the open redirect vulnerability.
WeaknessesCWE-601
Authorstheamanrawat
Template tagscvecve2022huntropen-redirectgiteavuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:gitea:gitea:*:*:*:*:*:*:*:*
Shodan: title:"Gitea"
Shodan: http.html:"powered by gitea version"
Shodan: http.title:"gitea"
Shodan: cpe:"cpe:2.3:a:gitea:gitea"
FOFA: body="powered by gitea version"
FOFA: title="gitea"
Google: intitle:"gitea"
https://github.com/go-gitea/gitea/commit/e3d8e92bdc67562783de9a76b5b7842b68daeb48 https://huntr.dev/bounties/4fb42144-ac70-4f76-a5e1-ef6b5e55dc0d https://nvd.nist.gov/vuln/detail/CVE-2022-1058
Source: ProjectDiscovery
References
6github.com
https://github.com/go-gitea/gitea/commit/e3d8e92bdc67562783de9a76b5b7842b68daeb48 github.com
https://github.com/go-gitea/gitea/pull/19175 github.com
https://github.com/go-gitea/gitea/pull/19186 huntr.devConfirmation
https://huntr.dev/bounties/4fb42144-ac70-4f76-a5e1-ef6b5e55dc0d nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-1058