Open
Description
CVE-2022-30781 references github.com/go-gitea/gitea, which may be a Go module.
Description:
Gitea before 1.6.7 does not escape git fetch remote.
Links:
- NIST: https://nvd.nist.gov/vuln/detail/CVE-2022-30781
- JSON: https://github.com/CVEProject/cvelist/tree/ca243b0e3ca2ed033b7059cba7b94617e6694471/2022/30xxx/CVE-2022-30781.json
- PR: Escape git fetch remote go-gitea/gitea#19487
- https://blog.gitea.io/2022/05/gitea-1.16.7-is-released/
See doc/triage.md for instructions on how to triage this report.
module: github.com/go-gitea/gitea
package: n/a
description: |
Gitea before 1.6.7 does not escape git fetch remote.
cves:
- CVE-2022-30781
links:
pr: https://github.com/go-gitea/gitea/pull/19487
context:
- https://blog.gitea.io/2022/05/gitea-1.16.7-is-released/