Описание
Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content (incomplete revocation cleanup in DeleteCollaboration)
A flaw was found in Gitea. Webhooks created by a collaborator continue to function even after their repository access is revoked. This incomplete revocation allows for the ongoing, real-time exfiltration of private repository content, leading to information disclosure.
Отчет
A flaw was found in Gitea's DeleteCollaboration function. When a collaborator's repository access is revoked, existing webhooks created by that user remain active instead of being disabled or removed. An attacker who previously held collaborator permissions can leverage these orphaned webhooks to continuously exfiltrate event payloads and sensitive private repository content without authorization.
Меры по смягчению последствий
To mitigate this vulnerability, repository administrators should manually audit and delete all webhooks created by a collaborator immediately upon revoking their access.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| OpenShift Pipelines | openshift-pipelines/pipelines-pipelines-as-code-controller-rhel9 | Affected | ||
| OpenShift Pipelines | openshift-pipelines/pipelines-pipelines-as-code-watcher-rhel9 | Affected |
Показывать по
Дополнительная информация
Статус:
7.5 High
CVSS3
Связанные уязвимости
Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content (incomplete revocation cleanup in `DeleteCollaboration`)
Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content
7.5 High
CVSS3