Impact
Gitea releases before 1.25.5 allow draft release data or attachments to be accessed without the required write permission. This improper access control (CWE‑284) permits any user with read access to a repository to view content that was intended to remain private until the release is published, potentially revealing confidential information. The CVE description does not explicitly mention effects on integrity or availability, so only confidentiality risk is confirmed.
Affected Systems
The vulnerability affects the Gitea Open Source Git Server. All releases prior to version 1.25.5 are impacted, regardless of sub‑version or patch level. Any environment running those earlier releases is at risk.
Risk and Exploitability
Based to a repository with read permission. The exploit requires only read access; no elevated privileges are needed. The CVSS score of 7.5 indicates a high severity level, while the EPSS score of <1% indicates a very low but non‑zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, yet the potential for sensitive data disclosure warrants immediate action.
OpenCVE Enrichment