{"id":"CVE-2019-11576","aliases":["GHSA-3393-r4p5-vhqh"],"url":"https://o3.security/vulnerability/CVE-2019-11576","summary":"Gitea Allows 1FA Even for 2FA-Enrolled Accounts","details":"Gitea before 1.8.0 allows 1FA for user accounts that have completed 2FA enrollment. If a user's credentials are known, then an attacker could send them to the API without requiring the 2FA one-time password.","published":"2019-04-28T02:29:00.250Z","modified":"2026-08-07T14:59:59.908409Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"code.gitea.io/gitea","fixedVersion":"1.8.0"}],"fix":{"url":"https://github.com/go-gitea/gitea/pull/6674","label":"go-gitea/gitea#6674"},"references":[{"type":"ADVISORY","url":"https://blog.gitea.io/2019/04/gitea-1.8.0-is-released/"},{"type":"FIX","url":"https://github.com/go-gitea/gitea/pull/6674"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T14:59:59.908409Z"}}