CVE-2026-60004: Gitea Gitea
Gitea는 코드 주입 취약성을 포함하여 저장소가있는 공격자가 악성 패치를 diffpatch API 엔드 포인트로 보내고 실행 가능한 Git 호크를 배치하고 Gitea 서비스 계정으로 쉘 명령을 실행할 수 있습니다.
CISA (English)
Gitea contains a code injection vulnerability that allows an attacker with repository write access to send a malicious patch to the diffpatch API endpoint to plant an executable Git hook and run shell commands as the Gitea service account.
- 공급업체
- Gitea
- 제품
- Gitea
- 취약점
- Gitea Code Injection Vulnerability
- 추가일
- 2026. 8. 25.
- CISA 조치 기한(미국 연방기관)
- 2026. 8. 28.
- 랜섬웨어 공격 악용
- 알 수 없음
- 약점(CWE)
- CWE-94
참고 자료
이 사이트는 정보 제공 목적으로 CISA 카탈로그를 요약한 것이며 보안 조언이 아닙니다. 공급업체 안내와 공식 권고를 따르세요.
최종 업데이트: · 카탈로그 버전 2026.10.02