FreshPorts - VuXML

This page displays vulnerability information about FreeBSD Ports.

The VUXML data was last processed by FreshPorts on 2024-04-28 07:09:48 UTC

List all Vulnerabilities, by package

List all Vulnerabilities, by date

k68

These are the vulnerabilities relating to the commit you have selected:

VuXML IDDescription
bd7592a1-cbfd-11ee-a42a-5404a6f3ca32gitea -- Prevent anonymous container access

Problem Description:

Even with RequireSignInView enabled, anonymous users can use docker pull to fetch public images.


Discovery 2024-01-24
Entry 2024-02-15
gitea
< 1.21.5

https://blog.gitea.com/release-of-1.21.5/
5ecfb588-d2f4-11ee-ad82-dbdfaa8acfc2gitea -- Fix XSS vulnerabilities

Problem Description:

  • The Wiki page did not sanitize author name
  • the reviewer name on a "dismiss review" comment is also affected
  • the migration page has some spots

Discovery 2024-02-23
Entry 2024-02-24
gitea
< 1.21.6

https://blog.gitea.com/release-of-1.21.6/