Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-20897

Опубликовано: 22 янв. 2026
Источник: debian

Описание

Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete LFS locks belonging to other repositories.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
gitearemovedpackage

Связанные уязвимости

CVSS3: 9.1
nvd
16 дней назад

Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete LFS locks belonging to other repositories.

github
16 дней назад

Gitea does not properly validate repository ownership when deleting Git LFS locks