Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.Test your applications
- Snyk ID SNYK-GOLANG-CODEGITEAIOGITEAMODULESCONTEXT-2841493
- published 22 May 2022
- disclosed 22 May 2022
- credit Unknown
How to fix?
code.gitea.io/gitea/modules/context to version 1.8.0 or higher.
Affected versions of this package are vulnerable to Improper Authentication. Allows 1FA for user accounts that have completed 2FA enrolment. If a user's credentials are known, then an attacker could send them to the API without requiring the 2FA one-time password.