Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-56750

Опубликовано: 13 авг. 2026
Источник: redhat
CVSS3: 8.1
EPSS Низкий

Описание

Gitea Remember-Me Token Theft Not Invalidating Attacker Session

A flaw was found in Gitea. An attacker who steals a user's "Remember Me" token can maintain unauthorized access to the user's account. This occurs because the system fails to invalidate the attacker's session even after the legitimate user logs out or changes their password. This vulnerability can lead to persistent unauthorized access and potential compromise of user data.

Отчет

An Important flaw exists in Gitea where the theft of a 'remember-me' token does not invalidate an attacker's session. This allows an attacker to retain unauthorized access to a user's account even after the legitimate user has logged out or changed their password, extending the window of compromise.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Pipelinesopenshift-pipelines-clientAffected
OpenShift Pipelinesopenshift-pipelines/pipelines-cli-tkn-rhel9Will not fix
OpenShift Pipelinesopenshift-pipelines/pipelines-opc-rhel9Will not fix
OpenShift Pipelinesopenshift-pipelines/pipelines-pipelines-as-code-cli-rhel9Will not fix
OpenShift Pipelinesopenshift-pipelines/pipelines-pipelines-as-code-controller-rhel9Will not fix
OpenShift Pipelinesopenshift-pipelines/pipelines-pipelines-as-code-watcher-rhel9Will not fix

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-613
https://bugzilla.redhat.com/show_bug.cgi?id=2515470code.gitea.io/gitea: Gitea: Unauthorized access due to remember-me token theft not invalidating attacker sessions.

EPSS

Процентиль: 27%
0.00342
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 9.1
nvd
26 дней назад

Gitea Remember-Me Token Theft Not Invalidating Attacker Session

CVSS3: 9.1
redos
27 дней назад

Уязвимость gitea

CVSS3: 9.1
redos
27 дней назад

Уязвимость gitea

github
около 2 месяцев назад

Gitea Remember-Me Token Theft Not Invalidating Attacker Session

EPSS

Процентиль: 27%
0.00342
Низкий

8.1 High

CVSS3