Gitea before 1.17.3 does not sanitize and escape refs in the git backend. Arguments to git commands are mishandled. References https://nvd.nist.gov/vuln/detail/CVE-2022-42968 https://github.com/go-gitea/gitea/pull/21463 https://github.com/go-gitea/gitea/releases/tag/v1.17.3 https://security.gentoo.org/glsa/202210-14 https://github.com/advisories/GHSA-w8xw-7crf-h23x