Описание
Gitea versions before 1.26.0 allow API users to fork a repository into an organization without first passing the CanCreateOrgRepo check, which can expose organization secrets.
A flaw was found in Gitea. An API (Application Programming Interface) endpoint responsible for forking repositories into an organization failed to properly check if a user had the necessary permissions to create repositories within that organization. This allowed a read-only organization member to bypass authorization controls and create a new repository. By exploiting this, an attacker could gain administrative privileges on the forked repository, enable Actions, and push malicious workflow files, leading to the exfiltration of sensitive organization-level Continuous Integration/Continuous Delivery (CI/CD) secrets, such as deploy keys and cloud credentials.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| OpenShift Pipelines | openshift-pipelines-client | Not affected | ||
| OpenShift Pipelines | openshift-pipelines/pipelines-cli-tkn-rhel9 | Not affected | ||
| OpenShift Pipelines | openshift-pipelines/pipelines-opc-rhel9 | Not affected | ||
| OpenShift Pipelines | openshift-pipelines/pipelines-pipelines-as-code-cli-rhel9 | Not affected | ||
| OpenShift Pipelines | openshift-pipelines/pipelines-pipelines-as-code-controller-rhel9 | Not affected | ||
| OpenShift Pipelines | openshift-pipelines/pipelines-pipelines-as-code-watcher-rhel9 | Not affected |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
8.1 High
CVSS3
Связанные уязвимости
Gitea versions before 1.26.0 allow API users to fork a repository into an organization without first passing the CanCreateOrgRepo check, which can expose organization secrets.
Gitea versions before 1.26.0 allow API users to fork a repository into ...
Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration
EPSS
8.1 High
CVSS3