CVE-2021-45328Open Redirect in Go-gitea Gitea

CWE-601Open Redirect5 documents3 sources
Severity
6.1MEDIUMNVD
EPSS
0.2%
top 60.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 8
Latest updateAug 21

Description

Gitea before 1.4.3 is affected by URL Redirection to Untrusted Site ('Open Redirect') via internal URLs.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

NVDgitea/gitea< 1.4.3

🔴Vulnerability Details

4
OSV
Open redirect in Gitea in github.com/go-gitea/gitea2024-08-21
GHSA
Open redirect in Gitea2022-02-09
OSV
Open redirect in Gitea2022-02-09
OSV
CVE-2021-45328: Gitea before 12022-02-08