Описание
Branch Protection Bypass via PR Retargeting Preserves Stale official Approval Flag
A flaw was found in Gitea. This vulnerability allows an attacker to bypass branch protection by retargeting a Pull Request (PR) that has a stale 'official' approval flag. This could lead to unauthorized code being merged into a protected branch, compromising code integrity.
Отчет
This is an Important flaw in Gitea that allows an attacker to bypass branch protection by manipulating pull requests with stale approval flags, potentially leading to unauthorized code merges and compromising code integrity. This is considered Important due to the potential for unauthorized code execution within a controlled environment, despite requiring specific user interaction.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| OpenShift Pipelines | openshift-pipelines-client | Not affected | ||
| OpenShift Pipelines | openshift-pipelines/pipelines-cli-tkn-rhel9 | Not affected | ||
| OpenShift Pipelines | openshift-pipelines/pipelines-opc-rhel9 | Not affected | ||
| OpenShift Pipelines | openshift-pipelines/pipelines-pipelines-as-code-cli-rhel9 | Not affected | ||
| OpenShift Pipelines | openshift-pipelines/pipelines-pipelines-as-code-controller-rhel9 | Not affected | ||
| OpenShift Pipelines | openshift-pipelines/pipelines-pipelines-as-code-watcher-rhel9 | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
7.7 High
CVSS3
Связанные уязвимости
Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag
Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag
EPSS
7.7 High
CVSS3