Описание
Gitea does not properly validate ownership when toggling OpenID URI visibility
Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2026-20904
- https://github.com/go-gitea/gitea/pull/36346
- https://github.com/go-gitea/gitea/pull/36361
- https://github.com/go-gitea/gitea/commit/ed5720af2ac94d74f822721c05b42b6148ff9c22
- https://blog.gitea.com/release-of-1.25.4
- https://github.com/go-gitea/gitea/releases/tag/v1.25.4
Пакеты
Наименование
github.com/go-gitea/gitea
go
Затронутые версииВерсия исправления
< 1.25.4
1.25.4
Связанные уязвимости
CVSS3: 6.5
nvd
15 дней назад
Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities.
CVSS3: 6.5
debian
15 дней назад
Gitea does not properly validate ownership when toggling OpenID URI vi ...