Описание
Gitea may send release notification emails for private repositories to users whose access has been revoked. When a repository is changed from public to private, users who previously watched the repository may continue to receive release notifications, potentially disclosing release titles, tags, and content.
Ссылки
- Release Notes
- Issue TrackingPatch
- Release Notes
- Broken Link
Уязвимые конфигурации
Конфигурация 1Версия до 1.25.4 (исключая)
cpe:2.3:a:gitea:gitea:*:*:*:*:*:-:*:*
EPSS
Процентиль: 6%
0.00025
Низкий
3.5 Low
CVSS3
Дефекты
CWE-284
Связанные уязвимости
CVSS3: 3.5
debian
15 дней назад
Gitea may send release notification emails for private repositories to ...
github
15 дней назад
Gitea may send release notification emails for private repositories to users whose access has been revoked
EPSS
Процентиль: 6%
0.00025
Низкий
3.5 Low
CVSS3
Дефекты
CWE-284