Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-68938

Опубликовано: 26 дек. 2025
Источник: redhat
CVSS3: 5.4

Описание

Gitea before 1.25.2 mishandles authorization for deletion of releases.

A flaw was found in Gitea. An incorrect authorization allows an authenticated user with minimal privileges to delete project releases, causing a loss of availability of project assets and distribution history.

Отчет

This issue will only cause the deletion of project assets and distribution history with no other security impact, such as memory corruption or arbitrary code execution. Additionally, exploitation requires an authenticated account with minimal privileges, limiting the exposure of this issue. Due to these reasons, this vulnerability has been rated with a moderate severity.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Pipelinesopenshift-pipelines/pipelines-pipelines-as-code-cli-rhel8Fix deferred
OpenShift Pipelinesopenshift-pipelines/pipelines-pipelines-as-code-cli-rhel9Fix deferred
OpenShift Pipelinesopenshift-pipelines/pipelines-pipelines-as-code-controller-rhel8Fix deferred
OpenShift Pipelinesopenshift-pipelines/pipelines-pipelines-as-code-controller-rhel9Fix deferred
OpenShift Pipelinesopenshift-pipelines/pipelines-pipelines-as-code-watcher-rhel8Fix deferred
OpenShift Pipelinesopenshift-pipelines/pipelines-pipelines-as-code-watcher-rhel9Fix deferred
OpenShift Pipelinesopenshift-pipelines/pipelines-pipelines-as-code-webhook-rhel8Fix deferred
OpenShift Pipelinesopenshift-pipelines/pipelines-pipelines-as-code-webhook-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-863
https://bugzilla.redhat.com/show_bug.cgi?id=2425454gitea: incorrect authorization for deletion of releases

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
ubuntu
3 месяца назад

Gitea before 1.25.2 mishandles authorization for deletion of releases.

CVSS3: 4.3
nvd
3 месяца назад

Gitea before 1.25.2 mishandles authorization for deletion of releases.

CVSS3: 4.3
debian
3 месяца назад

Gitea before 1.25.2 mishandles authorization for deletion of releases.

CVSS3: 4.3
github
3 месяца назад

Gitea mishandles authorization for deletion of releases

CVSS3: 5.3
fstec
3 месяца назад

Уязвимость системы управления Git-репозиториями Gitea, связанная с недостатками процедуры авторизации, позволяющая нарушителю оказать воздействие на доступность защищаемой информации

5.4 Medium

CVSS3