On 09/18, Kirill A. Korinsky wrote:
> On Tue, 15 Sep 2026 15:51:07 +0200,
> Anton Kasimov <[email protected]> wrote:
> > 
> > [1  <multipart/alternative (7bit)>]
> > [1.1  <text/plain; UTF-8 (8bit)>]
> > Please update Gitea in the stable branch as well.
> > 
> > The security issues fixed in the recent releases are fairly serious. In
> > configurations with anonymous read access to repositories enabled, some
> > of these issues may allow an attacker to gain full access to the server
> > with the privileges of the |_gitea|user.
> > 
> > The settings recommended by the port already mitigate the most critical
> > issues, but updating Gitea in stable would still be highly desirable.
> > 
> > Diff attached.
> > 
> >
> 
> It fixes serious enough things, for example:
> https://app.opencve.io/cve/CVE-2026-60004
> 
> And if new release can be built by go from 7.9, I think we should commit it.
> 
> pvk@, are you OK?

Sure, I'm OK with it.

-- 
With best regards,
Pavel Korovin

Reply via email to