Описание
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface. A user with read access to pull requests may be able to cancel auto-merges scheduled by other users.
Пакеты
Наименование
github.com/go-gitea/gitea
go
Затронутые версииВерсия исправления
< 1.25.4
1.25.4
Связанные уязвимости
CVSS3: 4.3
nvd
17 дней назад
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface. A user with read access to pull requests may be able to cancel auto-merges scheduled by other users.
CVSS3: 4.3
debian
17 дней назад
Gitea does not properly verify authorization when canceling scheduled ...