Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-22555

Опубликовано: 03 июл. 2026
Источник: redhat
CVSS3: 8.1
EPSS Низкий

Описание

Gitea versions before 1.26.0 allow API users to fork a repository into an organization without first passing the CanCreateOrgRepo check, which can expose organization secrets.

A flaw was found in Gitea. An API (Application Programming Interface) endpoint responsible for forking repositories into an organization failed to properly check if a user had the necessary permissions to create repositories within that organization. This allowed a read-only organization member to bypass authorization controls and create a new repository. By exploiting this, an attacker could gain administrative privileges on the forked repository, enable Actions, and push malicious workflow files, leading to the exfiltration of sensitive organization-level Continuous Integration/Continuous Delivery (CI/CD) secrets, such as deploy keys and cloud credentials.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Pipelinesopenshift-pipelines-clientNot affected
OpenShift Pipelinesopenshift-pipelines/pipelines-cli-tkn-rhel9Not affected
OpenShift Pipelinesopenshift-pipelines/pipelines-opc-rhel9Not affected
OpenShift Pipelinesopenshift-pipelines/pipelines-pipelines-as-code-cli-rhel9Not affected
OpenShift Pipelinesopenshift-pipelines/pipelines-pipelines-as-code-controller-rhel9Not affected
OpenShift Pipelinesopenshift-pipelines/pipelines-pipelines-as-code-watcher-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-639
https://bugzilla.redhat.com/show_bug.cgi?id=2496944code.gitea.io/gitea: Gitea: Organization Secret Exfiltration via API Fork Missing Authorization Check

EPSS

Процентиль: 23%
0.00305
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
nvd
около 1 месяца назад

Gitea versions before 1.26.0 allow API users to fork a repository into an organization without first passing the CanCreateOrgRepo check, which can expose organization secrets.

CVSS3: 8.1
debian
около 1 месяца назад

Gitea versions before 1.26.0 allow API users to fork a repository into ...

CVSS3: 8.1
redos
около 1 месяца назад

Уязвимость gitea

CVSS3: 8.1
github
2 месяца назад

Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration

EPSS

Процентиль: 23%
0.00305
Низкий

8.1 High

CVSS3