You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
We discussed this within the Gitea maintainers chat and think this is not a cve. If you give someone the privilege to execute arbitrary code on your server, they can execute arbitrary code on your server. That's like saying admin accounts on wordpress can do RCE because they can install plugins from third parties.
We never pretended to sandbox git hooks.
You can see in the PR which "fixed" that issue it only changed the default settings to mitigate the "issue" but not really fixed the problem: go-gitea/gitea#13058
search, files
Scanned versions: nixos-20.09: ba2ec48; nixos-unstable: 8133b9c.
Cc @disassembler
Cc @kolaente
Cc @Ma27
The text was updated successfully, but these errors were encountered: