Threat Advisory

Gitea Flaw Lets Attackers Execute Arbitrary Shell Commands

Threat: Vulnerability
Threat Actor Name: Watchdog
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities have been identified in Gitea, a self-hosted alternative to cloud-hosted GitHub, GitLab, and Bitbucket code hosting and DevOps platforms. Over 8,300 Internet-exposed Gitea instances are still unpatched against a critical security flaw exploited in ongoing remote code execution attacks. The affected version range is not explicitly stated in the article.

A code injection vulnerability allows authenticated attackers to execute arbitrary shell commands with the privileges of the Gitea service account by submitting malicious patches via the diffpatch API endpoint. Successful exploitation requires repository write access to repositories hosted on vulnerable servers, but Gitea comes with self-registration enabled by default, allowing unauthenticated attackers to register an account and create a new repository.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities have been identified in Gitea, a self-hosted alternative to cloud-hosted GitHub, GitLab, and Bitbucket code hosting and DevOps platforms. Over 8,300 Internet-exposed Gitea instances are still unpatched against a critical security flaw exploited in ongoing remote code execution attacks. The affected version range is not explicitly stated in the article.

A code injection vulnerability allows authenticated attackers to execute arbitrary shell commands with the privileges of the Gitea service account by submitting malicious patches via the diffpatch API endpoint. Successful exploitation requires repository write access to repositories hosted on vulnerable servers, but Gitea comes with self-registration enabled by default, allowing unauthenticated attackers to register an account and create a new repository.[emaillocker id="1283"]

:An authentication bypass flaw affects Gitea instances with reverse proxy authentication headers enabled. Threat actors were spotted abusing this vulnerability in the official Gitea Docker image.

RECOMMENDATION:

We recommend you to update Gitea to version 1.27.1.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu