๐ Gitea 1.24.7 is out!
This release brings important security fixes and improved stability.
๐ Fixed vulnerabilities include:
LFS authentication bypass
Arbitrary file access via template repos
Invalidated OAuth2 tokens accepted
๐งฉ 7 PRs merged โ huge thanks to our amazing community and security reporters!
๐ View more details https://blog.gitea.com/release-of-1.24.7/
#Gitea #DevOps #Git #OpenSource #Security
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnddaehgu3wwp6kyqpqqqqqqqz7nhdqz3uuwmzlflxt46lyu7zkuqhcapddhgz66c4ddynsjzg6ue nostr:nprofile1qy2hwumn8ghj7un9d3shjtnddaehgu3wwp6kyqpq26ntw5mnermmj0znhjhgdk8lh2af72sm8qfzq48umdlnhaj9kunsd7gxmg nostr:nprofile1qy2hwumn8ghj7un9d3shjtnddaehgu3wwp6kyqpqy8q62fgx5dpaztp5czjrfa7xek38dfsfaeg6pgp9x0lt7ryylvaqvkf3qs that domain resolves to an โinternal IPโ due to going through a proxy, and by default those are disabled to prevent โSSRFโ attacks. You can enable local domains through the configuration options listed in the error message
