sultanabubaker / intentionally-vulnerable-golang-project

0 stars 0 forks source link

CVE-2018-1000803 (Medium) detected in github.com/go-gitea/gitea-v1.2.3 #18

Open dev-mend-for-github-com[bot] opened 2 years ago

dev-mend-for-github-com[bot] commented 2 years ago

CVE-2018-1000803 - Medium Severity Vulnerability

Vulnerable Library - github.com/go-gitea/gitea-v1.2.3

Git with a cup of tea, painless self-hosted git service

Dependency Hierarchy: - :x: **github.com/go-gitea/gitea-v1.2.3** (Vulnerable Library)

Found in HEAD commit: 69a84c862836bec3e4be9a461b9e320cda5aeb94

Found in base branch: master

Vulnerability Details

Gitea version prior to version 1.5.1 contains a CWE-200 vulnerability that can result in Exposure of users private email addresses. This attack appear to be exploitable via Watch a repository to receive email notifications. Emails received contain the other recipients even if they have the email set as private. This vulnerability appears to have been fixed in 1.5.1.

Publish Date: 2018-10-08

URL: CVE-2018-1000803

CVSS 3 Score Details (5.3)

Base Score Metrics: - Exploitability Metrics: - Attack Vector: Network - Attack Complexity: Low - Privileges Required: None - User Interaction: None - Scope: Unchanged - Impact Metrics: - Confidentiality Impact: Low - Integrity Impact: None - Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-1000803

Release Date: 2018-10-08

Fix Resolution: v1.5.1