Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-25782

Опубликовано: 03 июл. 2026
Источник: debian
EPSS Низкий

Описание

Gitea versions before 1.25.5 look up tracked-time entries by time ID without scoping the lookup to the issue in the request URL, allowing deletion attempts to target entries from another issue.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
gitearemovedpackage

EPSS

Процентиль: 21%
0.00286
Низкий

Связанные уязвимости

CVSS3: 5.3
nvd
около 2 месяцев назад

Gitea versions before 1.25.5 look up tracked-time entries by time ID without scoping the lookup to the issue in the request URL, allowing deletion attempts to target entries from another issue.

CVSS3: 5.3
github
около 2 месяцев назад

Gitea versions before 1.25.5 look up tracked-time entries by time ID without scoping the lookup to the issue in the request URL, allowing deletion attempts to target entries from another issue.

EPSS

Процентиль: 21%
0.00286
Низкий