Description
An Authentication Bypass vulnerability exists in Gitea before 1.5.0, which could let a malicious user gain privileges. If captured, the TOTP code for the 2FA can be submitted correctly more than once.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-1043 | An Authentication Bypass vulnerability exists in Gitea before 1.5.0, which could let a malicious user gain privileges. If captured, the TOTP code for the 2FA can be submitted correctly more than once. |
Github GHSA |
GHSA-hfmf-q69j-6m5p | Reuse of one time passwords allowed in Gitea |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T04:39:20.655Z
Reserved: 2021-12-20T00:00:00.000Z
Link: CVE-2021-45331
No data.
Status : Modified
Published: 2022-02-09T18:15:10.013
Modified: 2024-11-21T06:32:05.937
Link: CVE-2021-45331
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA