In Gitea before 1.16.9, it was possible for users to add existing issues to projects. Due to improper access controls, an attacker could assign any issue to any project in Gitea (there was no permission check for fetching the issue). As a result, the attacker would get access to private issue titles.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2022-08-12T00:00:00

Updated: 2024-08-03T10:45:52.995Z

Reserved: 2022-08-12T00:00:00

Link: CVE-2022-38183

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-08-12T20:15:09.940

Modified: 2023-08-08T14:22:24.967

Link: CVE-2022-38183

cve-icon Redhat

No data.