Описание
In Gitea before 1.22.5, branch deletion permissions are not adequately enforced after merging a pull request.
A flaw was found in Gitea, a self-hosted Git service. After a pull request is merged, the system inadequately enforces branch deletion permissions. This allows an attacker with low privileges to delete branches without proper authorization, potentially leading to unauthorized changes to the repository's history and integrity.
Отчет
This vulnerability is rated Low for Red Hat OpenShift Pipelines. The flaw in Gitea, integrated with OpenShift Pipelines, allows a low-privileged attacker to delete branches without proper authorization after a pull request is merged. This could compromise the integrity and history of affected repositories.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| OpenShift Pipelines | openshift-pipelines/pipelines-pipelines-as-code-cli-rhel8 | Out of support scope | ||
| OpenShift Pipelines | openshift-pipelines/pipelines-pipelines-as-code-cli-rhel9 | Out of support scope | ||
| OpenShift Pipelines | openshift-pipelines/pipelines-pipelines-as-code-controller-rhel8 | Out of support scope | ||
| OpenShift Pipelines | openshift-pipelines/pipelines-pipelines-as-code-controller-rhel9 | Out of support scope | ||
| OpenShift Pipelines | openshift-pipelines/pipelines-pipelines-as-code-watcher-rhel8 | Out of support scope | ||
| OpenShift Pipelines | openshift-pipelines/pipelines-pipelines-as-code-watcher-rhel9 | Out of support scope | ||
| OpenShift Pipelines | openshift-pipelines/pipelines-pipelines-as-code-webhook-rhel8 | Out of support scope | ||
| OpenShift Pipelines | openshift-pipelines/pipelines-pipelines-as-code-webhook-rhel9 | Out of support scope |
Показывать по
Дополнительная информация
Статус:
EPSS
3.1 Low
CVSS3
Связанные уязвимости
In Gitea before 1.22.5, branch deletion permissions are not adequately enforced after merging a pull request.
In Gitea before 1.22.5, branch deletion permissions are not adequately enforced after merging a pull request.
In Gitea before 1.22.5, branch deletion permissions are not adequately ...
Gitea doesn't adequately enforce branch deletion permissions after merging a pull request.
EPSS
3.1 Low
CVSS3