Описание
Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs
A flaw was found in Gitea. This vulnerability allows for cross-repository information disclosure through the use of Org-Level Actions Run/Job Application Programming Interfaces (APIs). An attacker could exploit this to gain unauthorized access to sensitive information across different repositories.
Отчет
An authorization bypass vulnerability in Gitea's organization-level Actions REST API allows authenticated organization members to access workflow run and job details across all repositories within the organization. By querying the /api/v1/orgs/{org}/actions/runs or /api/v1/orgs/{org}/actions/jobs endpoints, an attacker can bypass per-repository access control lists (ACLs) to enumerate action execution data from private repositories or repositories to which they do not have access.
Меры по смягчению последствий
Disable Gitea Actions globally by setting ENABLE = false under the [actions] section in app.ini, or restrict organization membership to trusted users who already have read access to all organization repositories.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| OpenShift Pipelines | openshift-pipelines/pipelines-pipelines-as-code-watcher-rhel9 | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs
Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs
EPSS
6.5 Medium
CVSS3