Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-20750

Опубликовано: 22 янв. 2026
Источник: redhat
CVSS3: 9.1

Описание

Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be able to modify projects belonging to a different organization.

An access control flaw has been discovered in Gitea. Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be able to modify projects belonging to a different organization.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Pipelinesopenshift-pipelines/pipelines-opc-rhel9Not affected
OpenShift Pipelinesopenshift-pipelines/pipelines-pipelines-as-code-cli-rhel8Not affected
OpenShift Pipelinesopenshift-pipelines/pipelines-pipelines-as-code-cli-rhel9Not affected
OpenShift Pipelinesopenshift-pipelines/pipelines-pipelines-as-code-controller-rhel8Not affected
OpenShift Pipelinesopenshift-pipelines/pipelines-pipelines-as-code-controller-rhel9Not affected
OpenShift Pipelinesopenshift-pipelines/pipelines-pipelines-as-code-watcher-rhel8Not affected
OpenShift Pipelinesopenshift-pipelines/pipelines-pipelines-as-code-watcher-rhel9Not affected
OpenShift Pipelinesopenshift-pipelines/pipelines-pipelines-as-code-webhook-rhel8Not affected
OpenShift Pipelinesopenshift-pipelines/pipelines-pipelines-as-code-webhook-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Critical
Дефект:
CWE-284
https://bugzilla.redhat.com/show_bug.cgi?id=2432216gitea: Gitea Organization Projects Cross-Organization Authorization Bypass via Project ID (IDOR)

9.1 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.1
nvd
2 месяца назад

Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be able to modify projects belonging to a different organization.

CVSS3: 9.1
debian
2 месяца назад

Gitea does not properly validate project ownership in organization pro ...

github
2 месяца назад

Gitea does not properly validate project ownership in organization project operations

CVSS3: 9.1
fstec
2 месяца назад

Уязвимость системы управления Git-репозиториями Gitea, связанная с ошибками разграничения доступа, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 9.1
redos
около 1 месяца назад

Уязвимость gitea

9.1 Critical

CVSS3