Back to Database
Status published
Critical
CVE-2018-18926
Gitea before 1.5.4 allows remote code execution because it does...
Vulnerability Description
Gitea before 1.5.4 allows remote code execution because it does not properly validate session IDs. This is related to session ID handling in the go-macaron/session code for Macaron.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-18926
Credits & Attribution
No credits recorded in the NVD database.
More from gitea
View All →CVE-2022-42968
Gitea before 1.17.3 does not sanitize and escape refs in...
Unknown
0
CVE-2022-38795
In Gitea through 1.17.1, repo cloning can occur in the...
Medium
6.5
CVE-2022-38183
In Gitea before 1.16.9, it was possible for users to...
Medium
6.5
CVE-2022-30781
Gitea before 1.16.7 does not escape git fetch remote....
High
7.5
CVE-2022-27313
An arbitrary file deletion vulnerability in Gitea v1.16.3 allows attackers...
High
7.5
Affected Vendor
gitea
View all reports →Affected Software
gitea
Vulnerable Versions:
0
Timeline
Official Publish:
November 4th, 2018
Last Modified:
August 5th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.