Gitea
cpe:2.3:a:gitea:gitea:*:*:*:*:*:*:*
- < 1.21.2
A vulnerability in Gitea versions prior to 1.21.2 allows anonymous users to access private projects of other users. This issue arises from insufficient permission checks, which were addressed in the 1.21.2 release.
Exploitation of this vulnerability allows anonymous users to view private projects, potentially leading to unauthorized access to sensitive information or project details.
Users are advised to upgrade to Gitea version 1.21.2 or later, where this vulnerability has been fixed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.