Описание
Public-only repository tokens can update private PR head branches
A flaw was found in Gitea. This vulnerability allows an attacker to use tokens intended for public repositories to modify private pull request (PR) branches. This could lead to unauthorized changes in private code, compromising the integrity of the affected repositories.
Отчет
A flaw was found in Gitea where public-only repository tokens can be used to write to private pull request head branches. This authorization bypass allows an attacker with a valid public-only write:repository token to modify private repository branches through public base repository API endpoints, bypassing the public-only token restriction. This could lead to unauthorized changes in private code, compromising the integrity of affected repositories and potentially triggering private workflow executions when Actions is enabled.
Меры по смягчению последствий
Update to Gitea 1.27.0 or later. As a workaround, restrict the use of public-only tokens in environments where both public and private repositories with pull request relationships exist, or implement additional access controls at the API gateway level to prevent access to pull request update endpoints.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| OpenShift Pipelines | openshift-pipelines-client | Affected |
Показывать по
Дополнительная информация
Статус:
EPSS
9.6 Critical
CVSS3
Связанные уязвимости
Public-only repository tokens can update private PR head branches
Gitea: Public-only repository tokens can update private PR head branches
EPSS
9.6 Critical
CVSS3