REDHAT-BUG-2432205: High severity Gitea Gitea vulnerability
Gitea does not properly verify repository context when deleting attachments. A user who previously uploaded an attachment to a repository may be able to delete it after losing access to that repository by making the request through a different repository they can access.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2432205?
The severity of REDHAT-BUG-2432205 is classified as high, with a score of 7.
What does REDHAT-BUG-2432205 describe?
REDHAT-BUG-2432205 describes a vulnerability in Gitea where users can delete attachments from repositories they no longer have access to.
How do I fix REDHAT-BUG-2432205?
To fix REDHAT-BUG-2432205, update Gitea to the latest version that addresses this vulnerability.
Who is affected by REDHAT-BUG-2432205?
Users of Gitea who upload attachments to repositories are affected by REDHAT-BUG-2432205.
What should I do if I discover exploitation of REDHAT-BUG-2432205?
If you discover exploitation of REDHAT-BUG-2432205, report the incident to your security team immediately and implement the recommended updates.