Gitea
cpe:2.3:a:gitea:gitea:*:*:*:*:*:*:*
- <= 1.26.1
A vulnerability in Gitea's OAuth2 sign-in callback can improperly reactivate accounts that administrators have disabled. This issue is present in Gitea versions through 1.26.1. When a user authenticates via a linked external identity provider, the callback automatically restores their access, disregarding the administrator's disablement. As a result, the user regains full access to their repositories, organizations, and tokens, undermining administrative controls.
This vulnerability allows users to bypass account disablement, restoring their access and privileges, which could be problematic in cases of compromised accounts or employees who have left the organization.
To reproduce this vulnerability, first disable a user's account through the admin interface. Then, have the user sign in using an OAuth2 provider. The callback will reactivate the account, ignoring the previous disablement.
Users can upgrade to Gitea version 1.26.4, which addresses this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.