5 ms·
> Gitea is protected against both of these issues. Is Gitea's immunity just incidental because it was written by a different person, or is it due to a delibera
by tredre3 23d ago
> Gitea is protected against both of these issues.
Is Gitea's immunity just incidental because it was written by a different person, or is it due to a deliberate defensive system that prevents such bug/mistake from occurring?
- embedding-shape 23d agoVery interested in knowing too, since the issues seems to not be related at all, or similar, so now this must mean a Gitea "project leader" would only say this if they have some sort of layer that doesn't require them to manually patch issues individually. Meaning, firewall? Would be weird if that's built-in into Gitea though... Hmm.
- jonstaab 23d agoForgejo is a fork of gitea.
- ThePowerOfFuet 23d agoHence the question...
- Macha 23d agoIt looks like Gitea made the same fix (rm -r .git after template processing) back in February: https://github.com/go-gitea/gitea/commit/2176e84ab977011ff2bc3f3a9066020cc674f6b1#diff-491170640d4be1e5b696640c6d39f42b264825691b955aaa175935e182e9f0da# https://github.com/go-gitea/gitea/commit/2176e84ab977011ff2b... PR: https://github.com/go-gitea/gitea/pull/36734 https://github.com/go-gitea/gitea/pull/36734 So likely Gitea < 1.25.5 was vulnerable.
- fartfeatures 23d agoIt is unfortunate nobody tipped anyone off downstream.
- vanschelven 23d agogiven the fact that they communicated about this as a CVE, and Forgejo is a fork of gitea, one could say that this is on Forgejo though.
- fartfeatures 22d agoAgreed, I didn't realise there had been a CVE.
- dust-jacket 23d agoCVE AND release note not enough tipping off for you? it is absolutely not on maintainers of projects to proactively notify those who've forked the project. clear and transparent notices are exactly the right approach
- fartfeatures 22d agoApologies I didn't see there had been a CVE. I completely retract my statement.
- ntauthority 23d agoi like how this is a side effect of a bunch of assorted changes in a commit and PR solely described as "Fix path resolving" making it hard for anyone running Gitea to even know this is a security fix
- wvbdmp 23d agoIt’s explicitly listed as a security fix in the release notes, accompanied by a CVE: https://blog.gitea.com/release-of-1.25.5/ https://blog.gitea.com/release-of-1.25.5/
- tomxor 22d agoI'm not completely sure if this is supposed to be sincere, but it should be. It's not uncommon practice to omit the security implications on public facing commit messages when fixing secirity issues, so as to not to draw attention until it's ready for distribution.
- embedding-shape 23d agoSo not "Gitea is protected against both of these issues" but "Gitea fixed these issues earlier", which kind of feels like a less marketing-friendly version of what the Gitea employee said above. Why people can't just talk clearly and not try to oversell whatever they're doing? It's a disease at this point.