Impact
Gitea Open Source Git Server versions before 1.25.5 have an insufficient permission check on the tracked‑time list API endpoint. The flaw is an improper access control vulnerability (CWE‑284) that allows any user who can reach the API to retrieve time‑tracking records without proper authorization. The attack does not modify data or affect service availability; it only exposes potentially sensitive development activity and workload information to unauthorized parties.
Affected Systems
All installations of Gitea Open Source Git Server running a version older than 1.25.5 are impacted. The vulnerability is independent of deployment context and can be triggered by any user with network access to the API endpoint.
Risk and Exploitability
The EPSS score of less than 1% indicates a very low probability of exploitation at the time of this analysis, while a CVSS score of 5.3 reflects moderate severity. The vulnerable endpoint is presumably reachable over any network path that can access the Gitea instance, which is inferred from the fact that the flaw involves an API. No elevated privileges or system compromise are required, and the vulnerability does not compromise availability or data integrity. The exposure of time‑tracking information represents a confidentiality breach that could assist in further malicious reconnaissance.
OpenCVE Enrichment