S4E just found a high-severity finding from ssl robot vulnerability scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Apr 22, 2026

CVE-2021-45328 Scanner

CVE-2021-45328 Scanner - Open Redirect vulnerability in Gitea

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.3k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-45328
6.1
CVSS

Gitea before 1.4.3 is affected by URL Redirection to Untrusted Site ('Open Redirect') via internal URLs.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Gitea is an open-source, self-hosted Git service. It is widely used by developers and organizations to host and manage code repositories. The software offers features such as issue tracking, code review, and project management. Gitea is designed for lightweight operations and ease of installation across numerous platforms. It is often chosen for private Git hosting, providing users with control over their source code management. The software supports integration with other tools and services, enhancing the development process.

The Open Redirect vulnerability in Gitea allows an attacker to redirect users to arbitrary external websites. This vulnerability arises when URLs from internal sources are improperly validated. The flaw exists in the `redirect_to` parameter on the login page, which can be manipulated by attackers to facilitate external redirection. Users using Gitea versions before 1.4.3 are affected by this vulnerability.

Technically, the vulnerability is located in the login page's redirection system. The parameter `redirect_to`, used in the login process, allows insertion of unauthorized URLs. An attacker can exploit this by providing a malicious URL in this parameter, causing redirection upon a successful login attempt. The vulnerability resides in inadequate checking of the URL structure, allowing potentially dangerous URLs to execute the redirect action.

If exploited, the vulnerability can lead to users being unknowingly redirected to malicious websites. Such redirections can result in phishing attacks where sensitive information like login credentials may be stolen. It poses a significant risk in environments where users are unaware of the potential threats coming from external links. This vulnerability can also be used as a starting point for further attacks targeting the affected system.

REFERENCES

Solution Advice
  • Upgrade to Gitea version 1.4.3 or later to protect against open redirect vulnerabilities.
  • Implement additional URL validation checks to ensure safe redirection practices.
  • Regularly audit and review access controls and settings to ensure security best practices.
  • Educate users about safe browsing practices and risks associated with external redirects.
  • Utilize security tools and software updates to stay protected against emerging threats.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.