Friday, September 18, 2026

Re: Gitea stable update request

On 09/18, Kirill A. Korinsky wrote: > On Tue, 15 Sep 2026 15:51:07 +0200, > Anton Kasimov <kasimov.an@gmail.com> wrote: > > > > [1 <multipart/alternative (7bit)>] > > [1.1 <text/plain; UTF-8 (8bit)>] > > Please update Gitea in the stable branch as well. > > > > The security issues fixed in the recent releases are fairly serious. In > > configurations with anonymous read access to repositories enabled, some > > of these issues may allow an attacker to gain full access to the server > > with the privileges of the |_gitea|user. > > > > The settings recommended by the port already mitigate the most critical > > issues, but updating Gitea in stable would still be highly desirable. > > > > Diff attached. > > > > > > It fixes serious enough things, for example: > https://app.opencve.io/cve/CVE-2026-60004 > > And if new release can be built by go from 7.9, I think we should commit it. > > pvk@, are you OK? Sure, I'm OK with it. -- With best regards, Pavel Korovin

No comments:

Post a Comment