CVE-2021-45331

CRITICAL9.8EPSS 0.23%

Reuse of one time passwords allowed in Gitea in code.gitea.io/gitea

Published: 2/10/2022Modified: 4/3/2025
Also known as:GHSA-hfmf-q69j-6m5pBIT-gitea-2021-45331GO-2022-0315

Description

An Authentication Bypass vulnerability exists in Gitea before 1.5.0, which could let a malicious user gain privileges. If captured, the TOTP code for the 2FA can be submitted correctly more than once.

Affected packages (3)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1CRITICAL9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References (5)