TROYANOSYVIRUS
Zuruck zu CVEs

CVE-2025-68939

HIGH
8.2

Beschreibung

Gitea before 1.23.0 allows attackers to add attachments with forbidden file extensions by editing an attachment name via an attachment API.

CVE Details

CVSS v3.1 Bewertung8.2
SchweregradHIGH
CVSS VektorCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:L
AngriffsvektorNETWORK
KomplexitatHIGH
Erforderliche PrivilegienNONE
BenutzerinteraktionREQUIRED
Veroffentlicht12/26/2025
Zuletzt geandert1/2/2026
Quellenvd
Honeypot-Sichtungen0

Betroffene Produkte

gitea:gitea

Schwachen (CWE)

CWE-424

IOC Korrelationen

Keine Korrelationen erfasst

This product uses data from the NVD API but is not endorsed or certified by the NVD.