Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:34827
HistoryMar 25, 2022 - 6:18 a.m.

Open Redirect

2022-03-2506:18:06
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
21
open redirect
gitea
context vulnerability
malicious urls
software

EPSS

0.001

Percentile

41.5%

github.com/go-gitea/gitea is vulnerable to open redirect. The vulnerability exists in RedirectToFirst function in context.go due to the presence of backslashes in the Locations which allows an attacker to parse malicious URLs to redirect the user.

EPSS

0.001

Percentile

41.5%