Improper Access Control Affecting github.com/go-gitea/gitea/models package, versions <1.5.0


0.0
medium

Snyk CVSS

    Attack Complexity High
    Confidentiality High

    Threat Intelligence

    EPSS 0.22% (60th percentile)
Expand this section
NVD
9.8 critical

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk ID SNYK-GOLANG-GITHUBCOMGOGITEAGITEAMODELS-2397244
  • published 10 Feb 2022
  • disclosed 10 Feb 2022
  • credit cezar97

How to fix?

Upgrade github.com/go-gitea/gitea/models to version 1.5.0 or higher.

Overview

github.com/go-gitea/gitea/models is a self-hosted git service.

Affected versions of this package are vulnerable to Improper Access Control via the TOTP code for the two-factor authentication which can be submitted correctly more than once.