Описание
Gitea has insufficient permission checks for Composer package source links
CVE Description
Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which can expose private or internal package source information.
Summary
A critical vulnerability has been discovered in Gitea. It was already reported via (security@gitea.io) from (dev@noscope.com), and submitted an encrypted report.
Пакеты
code.gitea.io/gitea
<= 1.26.1
1.26.2
Связанные уязвимости
Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which can expose private or internal package source information.
Gitea versions up to and including 1.26.1 have insufficient permission ...
Уязвимость модели контроля доступа к реестру контейнеров системы управления Git-репозиториями Gitea, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации