Gitea server remote code execution explanation video.
Bypass login screen. Use arbitrary file read. Forge JWT tokens. Race condition and git hooks used to take control of the server.
Subscribe: https://www.youtube.com/c/KacperSzurekEN?sub_confirmation=1
Article: https://security.szurek.pl/gitea-1-4-0-unauthenticated-rce.html
My website: https://security.szurek.pl/
Twitter: https://twitter.com/kacperszurek
GitHub: https://github.com/kacperszurek/
Icon made by Freepik, Smashicons from www.flaticon.com
Download
0 formats
No download links available.
Race condition and git hooks vs Gitea server | NatokHD