Impact
During a transfer of a private repository to another user, Gitea grants temporary read access to the recipient as a collaborator so they can inspect the repository. When the transfer is later rejected or cancelled, the recipient’s collaboration is not revoked, allowing them to retain persistent read access to all private data, including code, issues, pull requests and the wiki. The repository owner receives no notification of this continued access, enabling the recipient to clone the entire repository. The vulnerability allows an attacker to obtain confidential information from a private repository that should be inaccessible after a transfer rejection.
Affected Systems
The issue affects Gitea Gitea installations running versions prior to the release of 28.0.0. The 28.0.0 update removes the retained read access while preserving any previous collaborations that existed before the transfer.
Risk and Exploitability
The vulnerability is exploitable through the normal web interface used to transfer repositories, so an attacker only needs to be the target of a transfer request or have permission to initiate it. Although the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, the impact of persistent read access to a private repository is substantial, potentially exposing sensitive code and project information. The lack of an EPSS figure suggests that exploitation may not be widespread at this time, but the absence of a KEV listing does not reduce the seriousness of the unauthorized access risk.
OpenCVE Enrichment