PT-2022-24262 · Gitea+1 · Gitea+1

Christian Pöschl

·

Published

2022-07-28

·

Updated

2024-06-10

·

CVE-2022-38183

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Gitea versions prior to 1.16.9
Description The issue is related to improper access controls in Gitea, allowing an attacker to assign any issue to any project. This results in the attacker gaining access to private issue titles due to the lack of permission checks for fetching issues.
Recommendations For versions prior to 1.16.9, update to version 1.16.9 or later to resolve the issue. As a temporary workaround, consider restricting access to project issue assignment until the update is applied.

Fix

Incorrect Permission

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-2311
ALT-PU-2022-2358
ALT-PU-2022-3074
BIT-GITEA-2022-38183
CVE-2022-38183
GHSA-FHV8-M4J4-CWW2
GO-2024-2769

Affected Products

Alt Linux
Gitea