Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8fwc-qjw5-rvgp

Опубликовано: 23 янв. 2026
Источник: github
Github: Прошло ревью
CVSS4: 2.3

Описание

Gitea may send release notification emails for private repositories to users whose access has been revoked

Gitea may send release notification emails for private repositories to users whose access has been revoked. When a repository is changed from public to private, users who previously watched the repository may continue to receive release notifications, potentially disclosing release titles, tags, and content.

Пакеты

Наименование

code.gitea.io/gitea

go
Затронутые версииВерсия исправления

< 1.25.4

1.25.4

EPSS

Процентиль: 15%
0.00237
Низкий

2.3 Low

CVSS4

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 3.5
redhat
7 месяцев назад

Gitea may send release notification emails for private repositories to users whose access has been revoked. When a repository is changed from public to private, users who previously watched the repository may continue to receive release notifications, potentially disclosing release titles, tags, and content.

CVSS3: 3.5
nvd
7 месяцев назад

Gitea may send release notification emails for private repositories to users whose access has been revoked. When a repository is changed from public to private, users who previously watched the repository may continue to receive release notifications, potentially disclosing release titles, tags, and content.

CVSS3: 3.5
debian
7 месяцев назад

Gitea may send release notification emails for private repositories to ...

CVSS3: 3.5
redos
6 месяцев назад

Уязвимость gitea

CVSS3: 3.5
redos
6 месяцев назад

Уязвимость gitea

EPSS

Процентиль: 15%
0.00237
Низкий

2.3 Low

CVSS4

Дефекты

CWE-284