logoalt Hacker News

Machayesterday at 10:35 PM3 repliesview on HN

It looks like Gitea made the same fix (rm -r .git after template processing) back in February: https://github.com/go-gitea/gitea/commit/2176e84ab977011ff2b...

PR: https://github.com/go-gitea/gitea/pull/36734

So likely Gitea < 1.25.5 was vulnerable.


Replies

embedding-shapetoday at 10:51 AM

So not "Gitea is protected against both of these issues" but "Gitea fixed these issues earlier", which kind of feels like a less marketing-friendly version of what the Gitea employee said above.

Why people can't just talk clearly and not try to oversell whatever they're doing? It's a disease at this point.

ntauthoritytoday at 6:20 AM

i like how this is a side effect of a bunch of assorted changes in a commit and PR solely described as "Fix path resolving" making it hard for anyone running Gitea to even know this is a security fix

show 2 replies
fartfeaturestoday at 1:29 AM

It is unfortunate nobody tipped anyone off downstream.