Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-58427

Опубликовано: 13 авг. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

Private org member list leaked via /members API endpoint — incomplete fix for PR #38145

A flaw was found in Gitea. An incomplete fix for a previous vulnerability allowed any authenticated user to enumerate all members of a private organization through the /members API endpoint. This information disclosure could expose sensitive details about an organization's internal structure and personnel to unauthorized individuals.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Pipelinesopenshift-pipelines/pipelines-pipelines-as-code-watcher-rhel9Affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-359
https://bugzilla.redhat.com/show_bug.cgi?id=2515456gitea.dev: Gitea: Information disclosure of private organization member lists

EPSS

Процентиль: 27%
0.00342
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
20 дней назад

Private org member list leaked via /members API endpoint — incomplete fix for PR #38145

CVSS3: 5.3
redos
20 дней назад

Уязвимость gitea

CVSS3: 5.3
redos
20 дней назад

Уязвимость gitea

github
около 1 месяца назад

Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145

EPSS

Процентиль: 27%
0.00342
Низкий

6.5 Medium

CVSS3

Уязвимость CVE-2026-58427