Vulnerabilities > Gitea > Critical

DATE CVE VULNERABILITY TITLE RISK
2022-10-16 CVE-2022-42968 Argument Injection or Modification vulnerability in Gitea
Gitea before 1.17.3 does not sanitize and escape refs in the git backend.
network
low complexity
gitea CWE-88
critical
9.8
2022-02-08 CVE-2021-45327 Interpretation Conflict vulnerability in Gitea
Gitea before 1.11.2 is affected by Trusting HTTP Permission Methods on the Server Side when referencing the vulnerable admin or user API.
network
low complexity
gitea CWE-436
critical
9.8