CVE-2019-11576Improper Authentication in Gitea

Severity
9.8CRITICALNVD
EPSS
0.4%
top 39.43%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 28
Latest updateMay 24

Description

Gitea before 1.8.0 allows 1FA for user accounts that have completed 2FA enrollment. If a user's credentials are known, then an attacker could send them to the API without requiring the 2FA one-time password.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

NVDgitea/gitea< 1.8.0

Patches

🔴Vulnerability Details

3
OSV
Gitea Allows 1FA Even for 2FA-Enrolled Accounts2022-05-24
GHSA
Gitea Allows 1FA Even for 2FA-Enrolled Accounts2022-05-24
OSV
CVE-2019-11576: Gitea before 12019-04-28