Skip to content

Disallow urlencoded new lines in git protocol paths if there is a port (#13521)#13525

Merged
lafriks merged 1 commit into
go-gitea:release/v1.12from
6543-forks:Backport2_13521
Nov 11, 2020
Merged

Disallow urlencoded new lines in git protocol paths if there is a port (#13521)#13525
lafriks merged 1 commit into
go-gitea:release/v1.12from
6543-forks:Backport2_13521

Conversation

@6543
Copy link
Copy Markdown
Member

@6543 6543 commented Nov 11, 2020

Backport #13521

@GiteaBot GiteaBot added the lgtm/need 1 This PR needs approval from one additional maintainer to be merged. label Nov 11, 2020
@GiteaBot GiteaBot added lgtm/done This PR has enough approvals to get merged. There are no important open reservations anymore. and removed lgtm/need 1 This PR needs approval from one additional maintainer to be merged. labels Nov 11, 2020
@lafriks lafriks merged commit 480efbd into go-gitea:release/v1.12 Nov 11, 2020
@lafriks lafriks deleted the Backport2_13521 branch November 11, 2020 21:48
@lafriks lafriks added topic/security Something leaks user information or is otherwise vulnerable. Should be fixed! type/bug and removed type/bug labels Nov 11, 2020
@stypr
Copy link
Copy Markdown

stypr commented Nov 13, 2020

LGTM

@abergmann
Copy link
Copy Markdown

CVE-2020-28991 was assigned to this issue.

@stypr
Copy link
Copy Markdown

stypr commented Nov 25, 2020

CVE-2020-28991 was assigned to this issue.

The impact is that this vulnerability can cause partial SSRF.
For some reason the impact was snipped off from the vulnerability summary by the CNA.

I'm keeping it an additional reference in here as an original reporter.

(This comment may change in the future)

@go-gitea go-gitea locked and limited conversation to collaborators Dec 14, 2020
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

lgtm/done This PR has enough approvals to get merged. There are no important open reservations anymore. topic/security Something leaks user information or is otherwise vulnerable. Should be fixed! type/bug

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants