Home
HIGH: 8.2 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:LDefault status
unaffected
Any version before 1.23.0
affected
Description
Gitea before 1.23.0 allows attackers to add attachments with forbidden file extensions by editing an attachment name via an attachment API.
Problem types
CWE-424 Improper Protection of Alternate Path
Product status
Any version before 1.23.0
References
blog.gitea.com/release-of-1.23.0/
github.com/go-gitea/gitea/releases/tag/v1.23.0
github.com/go-gitea/gitea/pull/32151
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.