Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qm72-8prh-g92x

Опубликовано: 03 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

Gitea versions before 1.25.5 look up tracked-time entries by time ID without scoping the lookup to the issue in the request URL, allowing deletion attempts to target entries from another issue.

Gitea versions before 1.25.5 look up tracked-time entries by time ID without scoping the lookup to the issue in the request URL, allowing deletion attempts to target entries from another issue.

EPSS

Процентиль: 21%
0.00286
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 5.3
nvd
около 2 месяцев назад

Gitea versions before 1.25.5 look up tracked-time entries by time ID without scoping the lookup to the issue in the request URL, allowing deletion attempts to target entries from another issue.

CVSS3: 5.3
debian
около 2 месяцев назад

Gitea versions before 1.25.5 look up tracked-time entries by time ID w ...

EPSS

Процентиль: 21%
0.00286
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-639