Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerability roundup 95: gitea-1.12.5: 1 advisory [7.2] #101156

Closed
1 task
ckauhaus opened this issue Oct 20, 2020 · 2 comments
Closed
1 task

Vulnerability roundup 95: gitea-1.12.5: 1 advisory [7.2] #101156

ckauhaus opened this issue Oct 20, 2020 · 2 comments
Labels
1.severity: security Issues which raise a security issue, or PRs that fix one

Comments

@ckauhaus
Copy link
Contributor

search, files

Scanned versions: nixos-20.09: ba2ec48; nixos-unstable: 8133b9c.

Cc @disassembler
Cc @kolaente
Cc @Ma27

@ckauhaus ckauhaus added the 1.severity: security Issues which raise a security issue, or PRs that fix one label Oct 20, 2020
@kolaente
Copy link
Member

We discussed this within the Gitea maintainers chat and think this is not a cve. If you give someone the privilege to execute arbitrary code on your server, they can execute arbitrary code on your server. That's like saying admin accounts on wordpress can do RCE because they can install plugins from third parties.
We never pretended to sandbox git hooks.

You can see in the PR which "fixed" that issue it only changed the default settings to mitigate the "issue" but not really fixed the problem: go-gitea/gitea#13058

@ckauhaus
Copy link
Contributor Author

ckauhaus commented Nov 4, 2020

disputed

@ckauhaus ckauhaus closed this as completed Nov 4, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
1.severity: security Issues which raise a security issue, or PRs that fix one
Projects
None yet
Development

No branches or pull requests

2 participants