GHSA-4wp3-8q92-mh8w

Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/02/GHSA-4wp3-8q92-mh8w/GHSA-4wp3-8q92-mh8w.json
Aliases
  • CVE-2021-45326
Published
2022-02-09T00:00:29Z
Modified
2023-09-15T20:20:04Z
Details

Cross Site Request Forgery (CSRF) vulnerability exists in Gitea before 1.5.2 via API routes.This can be dangerous especially with state altering POST requests.

References

Affected packages

Go / github.com/go-gitea/gitea

Source Details

Affected ranges

Type
SEMVER
Events
Introduced
0The exact introduced commit is unknown
Fixed
1.5.2

Ecosystem specific

{
    "affected_functions": [
        ""
    ]
}