Impact
The vulnerability allows any user with read access to a repository to view draft release data or attachments that should be hidden until publication. This improper access control undermines confidentiality by exposing confidential information that was intended to remain private. The flaw does not affect data integrity or availability, so the primary risk is leakage of sensitive content.
Affected Systems
All versions of the Gitea Open Source Git Server older than 1.25.5 are affected, regardless of patch level. Environments running these older releases are at risk, including any self‑hosted or hosted instances that have not upgraded.
Risk and Exploitability
The problem can be exploited by any account possessing read permission on the target repository; no elevated privileges are required. The assigned CVSS score of 7.5 marks this as a high‑severity issue. With an EPSS score of less than 1%, the probability of exploitation is low but not impossible. The vulnerability is not listed in the CISA KEV catalog. The lack of hardening of draft release visibility increases the possibility of sensitive data disclosure.
OpenCVE Enrichment