Описание
Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)
A flaw was found in Gitea. The Fork-PR Actions task, which handles pull requests from forked repositories, can be exploited to read data from a third private repository. This occurs due to a missing guard that should prevent unauthorized access via the collaborative-owner branch. A remote attacker could leverage this vulnerability to gain unauthorized access to sensitive information.
Отчет
A flaw was found in Gitea's Actions continuous integration runner logic for pull requests from forked repositories. Due to a missing permission boundary check on collaborative-owner branches, a Gitea Actions workflow triggered by a fork pull request can access unauthorized repository contexts. An authenticated remote user with write access to a fork can exploit this vulnerability to read sensitive data and configuration secrets from a third private repository accessible to the collaborative owner.
Меры по смягчению последствий
To mitigate this issue, repository administrators should disable Gitea Actions on affected repositories or restrict pull request workflows from fork repositories by configuring RUN_WORKFLOWS_FROM_FORK_PULL_REQUESTS to false in the Gitea configuration.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| OpenShift Pipelines | openshift-pipelines/pipelines-pipelines-as-code-watcher-rhel9 | Affected |
Показывать по
Дополнительная информация
Статус:
6.5 Medium
CVSS3
Связанные уязвимости
Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)
Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)
6.5 Medium
CVSS3