Description
In Gitea before 1.16.9, it was possible for users to add existing issues to projects. Due to improper access controls, an attacker could assign any issue to any project in Gitea (there was no permission check for fetching the issue). As a result, the attacker would get access to private issue titles.
Published: 2022-08-12
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2022-6551 In Gitea before 1.16.9, it was possible for users to add existing issues to projects. Due to improper access controls, an attacker could assign any issue to any project in Gitea (there was no permission check for fetching the issue). As a result, the attacker would get access to private issue titles.
Github GHSA Github GHSA GHSA-fhv8-m4j4-cww2 Gitea allowed assignment of private issues
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-03T10:45:52.995Z

Reserved: 2022-08-12T00:00:00.000Z

Link: CVE-2022-38183

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-08-12T20:15:09.940

Modified: 2024-11-21T07:15:57.377

Link: CVE-2022-38183

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses