Описание
In Gitea before 1.25.2, /api/v1/user has different responses for failed authentication depending on whether a username exists.
A flaw was found in Gitea. A remote attacker can exploit this vulnerability by observing different responses from the /api/v1/user endpoint during failed authentication attempts. This information disclosure allows the attacker to determine whether a specific username exists on the system.
Отчет
This vulnerability is rated Moderate as it allows for information disclosure through differing authentication responses on the /api/v1/user endpoint. This enables a remote attacker to enumerate valid usernames on affected systems, including OpenShift Pipelines deployments utilizing Gitea components.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| OpenShift Pipelines | openshift-pipelines/pipelines-pipelines-as-code-cli-rhel8 | Fix deferred | ||
| OpenShift Pipelines | openshift-pipelines/pipelines-pipelines-as-code-cli-rhel9 | Fix deferred | ||
| OpenShift Pipelines | openshift-pipelines/pipelines-pipelines-as-code-controller-rhel8 | Fix deferred | ||
| OpenShift Pipelines | openshift-pipelines/pipelines-pipelines-as-code-controller-rhel9 | Fix deferred | ||
| OpenShift Pipelines | openshift-pipelines/pipelines-pipelines-as-code-watcher-rhel8 | Fix deferred | ||
| OpenShift Pipelines | openshift-pipelines/pipelines-pipelines-as-code-watcher-rhel9 | Fix deferred | ||
| OpenShift Pipelines | openshift-pipelines/pipelines-pipelines-as-code-webhook-rhel8 | Fix deferred | ||
| OpenShift Pipelines | openshift-pipelines/pipelines-pipelines-as-code-webhook-rhel9 | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
5.3 Medium
CVSS3
Связанные уязвимости
In Gitea before 1.25.2, /api/v1/user has different responses for failed authentication depending on whether a username exists.
In Gitea before 1.25.2, /api/v1/user has different responses for faile ...
Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists
Уязвимость системы управления Git-репозиториями Gitea, связанная с несоответствием ответов на входящие запросы, позволяющая нарушителю оказать воздействие на конфиденциальность защищаемой информации
EPSS
5.3 Medium
CVSS3