Closed
Description
In GitHub Security Advisory GHSA-jr9c-h74f-2v28, there is a vulnerability in the following Go packages or modules:
Unit | Fixed | Vulnerable Ranges |
---|---|---|
code.gitea.io/gitea | 1.16.4 | <= 1.16.3 |
See doc/triage.md for instructions on how to triage this report.
packages:
- package: code.gitea.io/gitea
versions:
- introduced: TODO (earliest fixed "1.16.4", vuln range "<= 1.16.3")
description: Gitea 1.16.3 and prior is vulnerable to improper authorization. A patch
is available and is anticipated to be part of the 1.16.4 release.
published: 2022-03-11T00:02:35Z
last_modified: 2022-03-28T22:24:30Z
cves:
- CVE-2022-0905
ghsas:
- GHSA-jr9c-h74f-2v28
links:
context:
- https://github.com/advisories/GHSA-jr9c-h74f-2v28