On Sat, 19 Sep 2026 02:03:54 +0200,
Pavel Korovin <[email protected]> wrote:
> 
> On 09/18, Kirill A. Korinsky wrote:
> > On Tue, 15 Sep 2026 15:51:07 +0200,
> > Anton Kasimov <[email protected]> wrote:
> > > 
> > > [1  <multipart/alternative (7bit)>]
> > > [1.1  <text/plain; UTF-8 (8bit)>]
> > > Please update Gitea in the stable branch as well.
> > > 
> > > The security issues fixed in the recent releases are fairly serious. In
> > > configurations with anonymous read access to repositories enabled, some
> > > of these issues may allow an attacker to gain full access to the server
> > > with the privileges of the |_gitea|user.
> > > 
> > > The settings recommended by the port already mitigate the most critical
> > > issues, but updating Gitea in stable would still be highly desirable.
> > > 
> > > Diff attached.
> > > 
> > >
> > 
> > It fixes serious enough things, for example:
> > https://app.opencve.io/cve/CVE-2026-60004
> > 
> > And if new release can be built by go from 7.9, I think we should commit it.
> > 
> > pvk@, are you OK?
> 
> Sure, I'm OK with it.
> 

Thanks, commited to 7.9

-- 
wbr, Kirill

Reply via email to