REDHAT-BUG-2432219: Gitea Gitea vulnerability
Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could potentially be linked to a release in a different public repository, making it accessible to unauthorized users.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2432219?
The severity of REDHAT-BUG-2432219 is rated at 40, indicating a significant risk due to potential unauthorized access.
How do I fix REDHAT-BUG-2432219?
To fix REDHAT-BUG-2432219, ensure that proper validation checks are implemented in Gitea for repository ownership when linking attachments.
What types of repositories are affected by REDHAT-BUG-2432219?
REDHAT-BUG-2432219 affects Gitea private repositories and the public repositories they can potentially link to.
Who is at risk with the REDHAT-BUG-2432219 vulnerability?
Users of Gitea with private repositories are at risk as attachments may be inappropriately linked to public repositories.
When was REDHAT-BUG-2432219 published?
REDHAT-BUG-2432219 was published on January 22, 2026.