Описание
Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access
A flaw was found in Gitea. This vulnerability, identified as an Insecure Direct Object Reference (IDOR), exists within the issue-dependency removal function. A remote attacker with write access to issues in one repository can exploit this flaw to remove a dependency link to an issue in a private repository they are not authorized to access. This allows the attacker to tamper with issue-tracking states and inject comments into private repositories, leading to unauthorized write operations across private repository boundaries.
Отчет
A flaw was found in Gitea's issue-dependency removal logic. Due to insufficient authorization checks, a remote user with issue-write access in one repository can manipulate dependency relations pointing to an issue in a separate, restricted private repository. An attacker can exploit this IDOR flaw by targeting known issue IDs to remove dependency links and inject unauthorized system comments into private repositories beyond their permitted access scope, compromising cross-repository data integrity.
Меры по смягчению последствий
To mitigate this issue, restrict write access to repository issues to trusted users, or temporarily disable issue tracking on affected repositories until a patch is applied.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| OpenShift Pipelines | openshift-pipelines/pipelines-pipelines-as-code-controller-rhel9 | Affected | ||
| OpenShift Pipelines | openshift-pipelines/pipelines-pipelines-as-code-watcher-rhel9 | Affected |
Показывать по
Дополнительная информация
Статус:
6.5 Medium
CVSS3
Связанные уязвимости
Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access
Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access
6.5 Medium
CVSS3