Kryptovalutaticker:
sysadmin från Cyber Security News

Critical Gitea Arbitrary File Read Vulnerability Enables Remote Code Execution Attacks

Abinaya
Tuesday at 11:27
13 Visningar
0 Kommentarer
Critical Gitea Arbitrary File Read Vulnerability Enables Remote Code Execution Attacks

A critical security flaw in Gitea, tracked as CVE-2026-59774, allows unauthenticated remote attackers to read arbitrary files from vulnerable servers and potentially escalate the attack to remote code execution. The issue affects Gitea versions from 1.22.1 through 1.27.0 and is fixed in version 1.27.1. The vulnerability is documented as GHSA-6v53-hr58-556r and carries a Critical severity rating. It has a CVSS v3.1 vector of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, indicating that exploitation can occur remotely, requires no account, no user interaction, and can compromise confidentiality, integrity, and availability. The flaw exists in Gitea’s repository markup-rendering feature. An attacker can send a crafted request to the...

Läs hela artikeln hos källan.

Delta i diskussionen — kommentera, rösta och dela länkar.

Registrera
Var detta hjälpsamt?
Dela:

Kommentarer (0)

Vänligen logga in eller registrera dig för att delta i diskussionen

Inga kommentarer ännu. Bli först med att kommentera!