Описание
Repository Visibility Manipulation via Git Push Options
A flaw was found in Gitea. This vulnerability allows an attacker to manipulate repository visibility settings by leveraging specific Git push options. This could lead to unauthorized disclosure of repository information or unintended access control changes.
Отчет
This is rated as Important because a flaw in Gitea, as used in OpenShift Pipelines, allows an authenticated attacker with push access to a repository to manipulate its visibility via Git push options. This could lead to unauthorized disclosure of private repository contents or disruption of access to public repositories.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| OpenShift Pipelines | openshift-pipelines-client | Affected | ||
| OpenShift Pipelines | openshift-pipelines/pipelines-cli-tkn-rhel9 | Will not fix | ||
| OpenShift Pipelines | openshift-pipelines/pipelines-opc-rhel9 | Will not fix | ||
| OpenShift Pipelines | openshift-pipelines/pipelines-pipelines-as-code-cli-rhel9 | Will not fix | ||
| OpenShift Pipelines | openshift-pipelines/pipelines-pipelines-as-code-controller-rhel9 | Will not fix | ||
| OpenShift Pipelines | openshift-pipelines/pipelines-pipelines-as-code-watcher-rhel9 | Will not fix |
Показывать по
Дополнительная информация
Статус:
EPSS
7.1 High
CVSS3
Связанные уязвимости
Gitea: Repository Visibility Manipulation via Git Push Options
EPSS
7.1 High
CVSS3