An SSRF vulnerability in webhooks in Gitea through 1.5.0-rc2 and Gogs through 0.11.53 allows remote attackers to access intranet services.
| Software | From | Fixed in |
|---|---|---|
| gogs / gogs | - | 0.11.53.x |
| gitea / gitea | 1.5.0-rc2 | 1.5.0-rc2.x |
| gitea / gitea | 1.5.0-rc1 | 1.5.0-rc1.x |
| gitea / gitea | - | 1.5.0 |