Описание
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface. A user with read access to pull requests may be able to cancel auto-merges scheduled by other users.
EPSS
Процентиль: 3%
0.00017
Низкий
Дефекты
CWE-284
Связанные уязвимости
debian
16 дней назад
Gitea does not properly verify authorization when canceling scheduled ...
github
15 дней назад
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface
EPSS
Процентиль: 3%
0.00017
Низкий
Дефекты
CWE-284