Home
MEDIUM: 4.9 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:NDefault status
unaffected
Any version before 1.22.3
affected
Description
Gitea before 1.22.3 mishandles access to a private resource upon receiving an API token with scope limited to public resources.
Problem types
CWE-863 Incorrect Authorization
Product status
Any version before 1.22.3
References
blog.gitea.com/release-of-1.22.3/
github.com/go-gitea/gitea/releases/tag/v1.22.3
github.com/go-gitea/gitea/pull/32218
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.