Gitea
cpe:2.3:a:gitea:gitea:*:*:*:*:*:*:*
- < 1.21.8
A vulnerability in Gitea versions prior to 1.21.8 allows for the unintended disclosure of users' login times. This occurs through the 'lastlogintime' sort order on the '/explore/users' page, which can inadvertently reveal user activity.
Exploitation of this vulnerability could lead to unauthorized disclosure of user activity, specifically login times.
To reproduce this vulnerability, access the '/explore/users' page on a Gitea instance running a vulnerable version. Sort the user list by 'lastlogintime'. This will display users' login times, unintentionally revealing their activity.
Users are advised to upgrade to Gitea version 1.21.8 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.