Описание
Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be able to modify projects belonging to a different organization.
Ссылки
- Release Notes
- Issue TrackingPatch
- Issue TrackingPatch
- Release Notes
- Broken Link
Уязвимые конфигурации
Конфигурация 1Версия до 1.25.4 (исключая)
cpe:2.3:a:gitea:gitea:*:*:*:*:*:-:*:*
EPSS
Процентиль: 11%
0.00038
Низкий
9.1 Critical
CVSS3
Дефекты
CWE-284
Связанные уязвимости
CVSS3: 9.1
debian
17 дней назад
Gitea does not properly validate project ownership in organization pro ...
github
16 дней назад
Gitea does not properly validate project ownership in organization project operations
EPSS
Процентиль: 11%
0.00038
Низкий
9.1 Critical
CVSS3
Дефекты
CWE-284