4 ms·
Only posting here because I've been asked about it. Gitea is protected against both of these issues. (bias note: part of project leadership of Gitea) Edit: As
by techknowlogick 21d ago
Only posting here because I've been asked about it. Gitea is protected against both of these issues.
(bias note: part of project leadership of Gitea)
Edit: As a note, security incidents happen to everyone and we shouldn't shame anyone for reporting them, especially as that'd otherwise cause less issues to be reported overall.
- tredre3 21d ago> Gitea is protected against both of these issues. Is Gitea's immunity just incidental because it was written by a different person, or is it due to a deliberate defensive system that prevents such bug/mistake from occurring?
- embedding-shape 21d agoVery interested in knowing too, since the issues seems to not be related at all, or similar, so now this must mean a Gitea "project leader" would only say this if they have some sort of layer that doesn't require them to manually patch issues individually. Meaning, firewall? Would be weird if that's built-in into Gitea though... Hmm.
- jonstaab 21d agoForgejo is a fork of gitea.
- ThePowerOfFuet 21d agoHence the question...
- Macha 21d agoIt looks like Gitea made the same fix (rm -r .git after template processing) back in February: https://github.com/go-gitea/gitea/commit/2176e84ab977011ff2bc3f3a9066020cc674f6b1#diff-491170640d4be1e5b696640c6d39f42b264825691b955aaa175935e182e9f0da# https://github.com/go-gitea/gitea/commit/2176e84ab977011ff2b... PR: https://github.com/go-gitea/gitea/pull/36734 https://github.com/go-gitea/gitea/pull/36734 So likely Gitea < 1.25.5 was vulnerable.
- fartfeatures 20d agoIt is unfortunate nobody tipped anyone off downstream.
- vanschelven 20d agogiven the fact that they communicated about this as a CVE, and Forgejo is a fork of gitea, one could say that this is on Forgejo though.
- fartfeatures 19d agoAgreed, I didn't realise there had been a CVE.
- dust-jacket 20d agoCVE AND release note not enough tipping off for you? it is absolutely not on maintainers of projects to proactively notify those who've forked the project. clear and transparent notices are exactly the right approach
- fartfeatures 19d agoApologies I didn't see there had been a CVE. I completely retract my statement.
- ntauthority 20d agoi like how this is a side effect of a bunch of assorted changes in a commit and PR solely described as "Fix path resolving" making it hard for anyone running Gitea to even know this is a security fix
- wvbdmp 20d agoIt’s explicitly listed as a security fix in the release notes, accompanied by a CVE: https://blog.gitea.com/release-of-1.25.5/ https://blog.gitea.com/release-of-1.25.5/
- deleted 21d ago[deleted]
- deleted 21d ago[deleted]
- dabeeeenster 21d agoYour note is really important! Thanks for adding it. None of us are perfect.
- philipwhiuk 20d agoIf you upgraded from < 1.25.5