Описание
Privilege Escalation via Access Token Scope Escalation in API
A flaw was found in Gitea. This vulnerability allows an attacker to escalate their privileges by manipulating the scope of an access token within the API. This means an attacker could gain unauthorized access to sensitive functions or data, potentially leading to full control over affected resources.
Отчет
Important: An authenticated attacker with a limited-scope API token in Gitea could escalate their privileges. This is due to a flaw in how Gitea's API processes basic authentication with tokens, allowing the creation of new tokens with elevated scopes beyond the original token's permissions. Red Hat OpenShift Pipelines does not deploy Gitea web servers.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| OpenShift Pipelines | openshift-pipelines-client | Not affected | ||
| OpenShift Pipelines | openshift-pipelines/pipelines-cli-tkn-rhel9 | Not affected | ||
| OpenShift Pipelines | openshift-pipelines/pipelines-opc-rhel9 | Not affected | ||
| OpenShift Pipelines | openshift-pipelines/pipelines-pipelines-as-code-cli-rhel9 | Not affected | ||
| OpenShift Pipelines | openshift-pipelines/pipelines-pipelines-as-code-controller-rhel9 | Not affected | ||
| OpenShift Pipelines | openshift-pipelines/pipelines-pipelines-as-code-watcher-rhel9 | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
8.8 High
CVSS3
Связанные уязвимости
Privilege Escalation via Access Token Scope Escalation in API
Gitea: Privilege Escalation via Access Token Scope Escalation in API
EPSS
8.8 High
CVSS3