Gitea
cpe:2.3:a:gitea:gitea:*:*:*:*:*:*:*
- >= 1.25.0, < 1.25.4
A vulnerability in Gitea allows release notification emails for private repositories to be sent to users whose access has been revoked. When a repository is switched from public to private, users who previously watched the repository may still receive release notifications. This can lead to the unintentional disclosure of release titles, tags, and content.
This vulnerability can result in unauthorized disclosure of release information from private repositories.
To reproduce this vulnerability, watch a public repository and then have it changed to private. After access has been revoked, release notification emails may still be sent, containing details that should remain confidential.
Users can manually check and update their repository access permissions. Gitea Cloud instances will be automatically upgraded to version 1.26.0, which addresses this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.