Описание
Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities.
Ссылки
- Release Notes
- Issue TrackingPatch
- Issue TrackingPatch
- Release Notes
- Broken Link
Уязвимые конфигурации
Конфигурация 1Версия до 1.25.4 (исключая)
cpe:2.3:a:gitea:gitea:*:*:*:*:*:-:*:*
EPSS
Процентиль: 1%
0.00011
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-284
Связанные уязвимости
CVSS3: 6.5
redhat
2 месяца назад
Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities.
CVSS3: 6.5
debian
2 месяца назад
Gitea does not properly validate ownership when toggling OpenID URI vi ...
github
2 месяца назад
Gitea does not properly validate ownership when toggling OpenID URI visibility
EPSS
Процентиль: 1%
0.00011
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-284