Описание
Gitea versions up to and including 1.26.1 allow the Allow edits from maintainers permission path to authorize commits to repositories that the user can read but should not be able to write.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| gitea | removed | package |
EPSS
Процентиль: 22%
0.00291
Низкий
Связанные уязвимости
CVSS3: 8.5
nvd
около 2 месяцев назад
Gitea versions up to and including 1.26.1 allow the Allow edits from maintainers permission path to authorize commits to repositories that the user can read but should not be able to write.
CVSS3: 8.5
github
2 месяца назад
Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo
EPSS
Процентиль: 22%
0.00291
Низкий