Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 768324 (CVE-2021-3382) - <www-apps/gitea-1.13.2: Multiple vulnerabilities (CVE-2021-3382)
Summary: <www-apps/gitea-1.13.2: Multiple vulnerabilities (CVE-2021-3382)
Status: RESOLVED FIXED
Alias: CVE-2021-3382
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL: https://github.com/go-gitea/gitea/rel...
Whiteboard: ~3 [noglsa]
Keywords: PullRequest
Depends on:
Blocks:
 
Reported: 2021-02-02 07:47 UTC by tastytea
Modified: 2021-02-09 09:19 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description tastytea 2021-02-02 07:47:45 UTC
Release 1.13.2:
 - Prevents a panic: https://github.com/go-gitea/gitea/pull/14405
 - Adds secure/httpOnly attributes to the lang cookie: https://github.com/go-gitea/gitea/issues/9690
 - Makes the internal ssh server respect Ciphers, MACs and KeyExchanges settings: https://github.com/go-gitea/gitea/issues/14518

Reproducible: Always
Comment 1 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2021-02-02 15:17:35 UTC
Thank you for the report! Minor thing, we only put the version in the bug summary once the fixes version(s) are in tree.

Maintainer, please bump to 1.13.2.
Comment 2 Larry the Git Cow gentoo-dev 2021-02-09 08:56:44 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=7fc953597375ded58d3572b491de7f60db54737b

commit 7fc953597375ded58d3572b491de7f60db54737b
Author:     Pierre-Olivier Mercier <nemunaire@nemunai.re>
AuthorDate: 2021-02-05 19:59:36 +0000
Commit:     Sam James <sam@gentoo.org>
CommitDate: 2021-02-09 08:52:55 +0000

    www-apps/gitea: bump to 1.13.2
    
    Bug: https://bugs.gentoo.org/768324
    Package-Manager: Portage-3.0.13, Repoman-3.0.2
    Signed-off-by: Pierre-Olivier Mercier <nemunaire@nemunai.re>
    Signed-off-by: Sam James <sam@gentoo.org>

 www-apps/gitea/Manifest            |   1 +
 www-apps/gitea/gitea-1.13.2.ebuild | 129 +++++++++++++++++++++++++++++++++++++
 2 files changed, 130 insertions(+)