Home
MEDIUM: 5.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:NDefault status
unaffected
Any version before 1.22.2
affected
Description
Gitea before 1.22.2 sometimes mishandles the propagation of token scope for access control within one of its own package registries.
Problem types
CWE-441 Unintended Proxy or Intermediary ('Confused Deputy')
Product status
Any version before 1.22.2
References
blog.gitea.com/release-of-1.22.2/
github.com/go-gitea/gitea/releases/tag/v1.22.2
github.com/go-gitea/gitea/pull/31967
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.