Gitea Path Resolution Vulnerability: Assess Your Exposure Now
- Severity
- HIGH
- Affected component
- code.gitea.io/gitea (go)
- Affected versions
- < 1.27.0 or < 1.27.0 or < 1.26.3 or < 1.27.0 or < 1.8.0 or < 1.26.2 or >= 1.1.0, < 1.12.6 or < 1.25.0 or < 1.26.3 or < 1.27.0 or < 1.26.4 or < 1.22.1 or < 1.16.5 or < 1.27.0 or < 1.7.1 or < 1.26.3 or < 1.27.0 or < 1.27.0 or < 1.27.0 or < 1.27.0 or < 1.26.3 or < 1.27.0 or >= 1.23.0, < 1.26.3 or < 1.21.2 or < 1.27.0 or < 1.26.2 or < 1.22.2 or < 1.25.4 or < 1.17.2 or < 1.27.0 or < 1.26.2 or < 1.27.0 or >= 1.25.0, < 1.26.0 or < 1.27.0 or < 1.26.2 or < 1.26.2 or < 1.19.4 or < 1.25.2 or < 1.27.0 or < 1.26.2 or < 1.26.3 or < 1.22.2 or < 1.16.0-rc1 or < 1.16.9 or < 1.26.0 or < 1.27.0 or < 1.27.0 or < 1.27.0 or < 1.16.4 or < 1.13.4 or < 1.26.4 or >= 1.5.0, < 1.26.3 or < 1.27.0 or < 1.13.6 or < 1.5.2 or < 1.5.0 or >= 1.22.0, < 1.26.2 or < 1.25.4 or < 1.20.1 or >= 1.7.2, < 1.7.4 or < 1.27.0 or < 1.6.3 or < 1.21.8 or < 1.16.4 or < 1.27.0 or < 1.27.0 or < 1.26.2 or < 1.27.0 or < 1.16.7 or < 1.25.2 or < 1.6.0 or < 1.27.0 or < 1.16.9 or < 1.27.0 or < 1.27.0 or < 1.27.0 or < 1.27.0 or < 1.27.0 or < 1.26.0 or < 1.26.4 or < 1.22.5 or < 1.26.3 or < 1.26.4 or < 1.27.0 or < 1.27.0 or < 1.27.0 or < 1.26.3 or >= 1.22.3, < 1.26.2 or < 1.27.0 or < 1.27.0 or < 1.22.3 or < 1.27.0 or < 1.27.0 or < 1.11.2 or < 1.5.0 or < 1.13.6 or < 1.16.4 or < 1.16.7 or < 1.16.4 or < 1.16.9 or < 1.12.0 or < 1.13.4 or < 1.5.2 or < 1.6.0 or < 1.17.3 or < 1.19.4 or < 1.7.1 or < 1.16.0-rc1 or < 1.17.2 or < 1.16.5 or >= 1.9.0, < 1.13.2 or < 1.16.9 or < 1.22.1 or < 1.25.2 or < 1.21.2 or < 1.22.2 or < 1.22.2 or < 1.20.1 or < 1.21.8 or < 1.22.5 or < 1.22.3 or < 1.25.2 or < 1.25.4 or < 1.25.4 or < 1.25.4 or < 1.25.4 or < 1.25.4 or < 1.25.4 or < 1.25.4 or < 1.25.4 or < 1.25.4 or < 1.26.2 or < 1.25.0 or < 1.26.2 or >= 1.25.0, < 1.26.0 or < 1.26.2 or < 1.26.2 or < 1.26.2 or < 1.26.0 or < 1.26.0 or < 1.26.2 or >= 1.22.3, < 1.26.2 or < 1.26.2 or < 1.26.3 or < 1.26.3 or < 1.26.3 or < 1.26.4 or < 1.26.3 or < 1.26.3 or >= 1.23.0, < 1.26.3 or < 1.26.3 or < 1.26.4 or >= 1.5.0, < 1.26.3 or >= 1.22.0, < 1.26.2 or < 1.26.0 or < 1.26.4 or < 1.26.3 or < 1.26.4 or < 1.26.3
- Patched version
- 1.25.5
Gitea versions before 1.25.5 reportedly mishandle path resolution during template repository generation, potentially allowing unauthorized read or write access.
What happened
Gitea versions before 1.25.5 appear to have a vulnerability in the way they handle path resolution during template repository generation. This mishandle could allow an attacker to read or write through symlinked or otherwise non-regular paths. The vulnerability is under investigation and has not been exploited in the wild as of the latest reports. Users of affected versions should take immediate action to assess their exposure and apply the recommended upgrade.
The vulnerability affects various versions of the code.gitea.io/gitea package. The specific versions impacted are detailed in the affected components section. It is crucial for users to check their current version against this list to determine if they are vulnerable.
What to do about it
- Upgrade to Gitea version 1.25.5 or later to mitigate the vulnerability.
- Check your current Gitea version against the affected components list to assess your exposure.
- Monitor the primary sources for updates on the vulnerability and any additional patches that may be released.
- If you are using a version of Gitea before 1.25.5, consider this a high-priority update.
- No official fix has been published for versions not listed as patched. Monitor the sources below for updates.
How 0Day would have caught this
code.gitea.io/gitea is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
If you are using a version of Gitea before 1.25.5, you may be affected. Check the affected components list for specific version details.
What should I do right now?
Upgrade to Gitea version 1.25.5 or later immediately. Check your current version against the affected components list to confirm your exposure.
Is there an official patch available?
Yes, Gitea version 1.25.5 is the patched version. Upgrade to this version or later to address the vulnerability.
Where can I find more information about this vulnerability?
Consult the primary sources listed in the incident data for the most accurate and up-to-date information.