Описание
Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)
A flaw was found in Gitea. An authenticated remote attacker with repository write permission could bypass the attachment extension allowlist via the web release edit form. This vulnerability allows the attacker to rename existing release attachments to forbidden file extensions, potentially leading to the distribution of malicious files or stored Cross-Site Scripting (XSS) attacks.
Отчет
The vulnerability, a Moderate attachment allowlist bypass in Gitea, allows an authenticated attacker to upload files with forbidden extensions by manipulating the web release edit form. However, Red Hat products are not affected by this flaw as the vulnerable code from routers/web/repo/release.go is not present in shipped components.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| OpenShift Pipelines | openshift-pipelines-client | Not affected | ||
| OpenShift Pipelines | openshift-pipelines/pipelines-cli-tkn-rhel9 | Not affected | ||
| OpenShift Pipelines | openshift-pipelines/pipelines-opc-rhel9 | Not affected | ||
| OpenShift Pipelines | openshift-pipelines/pipelines-pipelines-as-code-cli-rhel9 | Not affected | ||
| OpenShift Pipelines | openshift-pipelines/pipelines-pipelines-as-code-controller-rhel9 | Not affected | ||
| OpenShift Pipelines | openshift-pipelines/pipelines-pipelines-as-code-watcher-rhel9 | Not affected |
Показывать по
Дополнительная информация
Статус:
6.5 Medium
CVSS3
Связанные уязвимости
Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)
Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)
6.5 Medium
CVSS3