In Jenkins versions 2.56 and earlier, including LTS 2.46.1 and earlier a critical severity vulnerability CVE-2017-1000353 was detected. This vulnerability allows unauthenticated attackers to execute arbitrary code by sending a serialized Java SignedObject to the Jenkins CLI, bypassing existing blacklist-based protections. To address this issue, users should upgrade Jenkins to version 2.57 or LTS 2.46.2 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2017-1000353.
Read more Newsflash Developer ToolsIn Gitea versions before 1.22.3 a medium severity vulnerability CVE-2025-68941 was detected. This vulnerability allows attackers to access private resources by using an API token that is restricted to public scopes, due to improper enforcement of access controls. To address this issue, users should upgrade Gitea to version 1.22.3 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-68941.
Read more Newsflash Developer ToolsIn Gitea versions before 1.22.5 a low severity vulnerability CVE-2025-68940 was detected. This vulnerability allows attackers to delete branches without proper authorization after a pull request has been merged, due to insufficient enforcement of branch deletion permissions. To address this issue, users should upgrade Gitea to version 1.22.5 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-68940.
In Gitea versions before 1.23.0 a high severity vulnerability CVE-2025-68939 was detected. This vulnerability allows attackers to bypass forbidden file extension restrictions by modifying attachment names through the Attachment API, enabling the upload of potentially dangerous files. To address this issue, users should upgrade Gitea to version 1.23.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-68939.
Read more Newsflash Developer ToolsIn Gitea versions before 1.25.2 a medium severity vulnerability CVE-2025-68938 was detected. This vulnerability allows attackers to delete releases without proper authorization due to insufficient permission checks during the release deletion process. To address this issue, users should upgrade Gitea to version 1.25.2 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-68938.
Read more Developer ToolsIn Gitea versions before 1.22.2 a medium severity vulnerability CVE-2025-68944 was detected. This vulnerability allows attackers to gain unauthorized access by exploiting improper propagation of token scopes within the package registry, potentially leading to access beyond intended permissions. To address this issue, users should upgrade Gitea to version 1.22.2 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-68944.
Read more Developer ToolsIn Gitea versions before 1.21.8 a medium severity vulnerability CVE-2025-68943 was detected. This vulnerability allows attackers to discover users’ login times via the Explore/Users sorting functionality. To address this issue, users should upgrade Gitea to version 1.21.8 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-68943.
Read more Developer ToolsIn Gitea versions before 1.22.2 a medium severity vulnerability CVE-2025-68942 was detected. This vulnerability allows attackers to perform cross-site scripting (XSS) via the tag and branch search input box due to improper rendering of input as v-html instead of v-text. To address this issue, users should upgrade Gitea to version 1.22.2 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-68942.
Read more Developer ToolsIn Gitea versions before 1.22.3 a medium severity vulnerability CVE-2025-68941 was detected. This vulnerability allows attackers to bypass API token scope restrictions and access private resources when a token is limited to public resources. To address this issue, users should upgrade Gitea to version 1.22.3 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-68941.
Read more Developer Tools