{"id":"GHSA-hf6f-jq25-8gq9","summary":"Gitea Remote Code Execution (RCE)","details":"Gitea before 1.5.4 allows remote code execution because it does not properly validate session IDs. This is related to session ID handling in the go-macaron/session code for Macaron.","aliases":["CVE-2018-18926","GO-2022-0844"],"modified":"2024-08-21T15:58:58.172948Z","published":"2022-02-15T01:57:18Z","database_specific":{"cwe_ids":["CWE-94"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2021-05-12T18:25:03Z","nvd_published_at":null},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-18926"},{"type":"WEB","url":"https://github.com/go-gitea/gitea/issues/5140"},{"type":"WEB","url":"https://github.com/go-gitea/gitea/pull/5177"},{"type":"WEB","url":"https://github.com/go-gitea/gitea/commit/aeb5655c25053bdcd7eee94ea37df88468374162"}],"affected":[{"package":{"name":"code.gitea.io/gitea","ecosystem":"Go","purl":"pkg:golang/code.gitea.io/gitea"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.5.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/02/GHSA-hf6f-jq25-8gq9/GHSA-hf6f-jq25-8gq9.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}