Описание
Gitea does not properly validate ownership when toggling OpenID URI visibility
Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2026-20904
- https://github.com/go-gitea/gitea/pull/36346
- https://github.com/go-gitea/gitea/pull/36361
- https://github.com/go-gitea/gitea/commit/ed5720af2ac94d74f822721c05b42b6148ff9c22
- https://blog.gitea.com/release-of-1.25.4
- https://github.com/go-gitea/gitea/releases/tag/v1.25.4
Пакеты
Наименование
github.com/go-gitea/gitea
go
Затронутые версииВерсия исправления
< 1.25.4
1.25.4
Связанные уязвимости
CVSS3: 6.5
redhat
2 месяца назад
Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities.
CVSS3: 6.5
nvd
2 месяца назад
Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities.
CVSS3: 6.5
debian
2 месяца назад
Gitea does not properly validate ownership when toggling OpenID URI vi ...