Слабость
Gitea versions up to and including 1.26.1 allow the Allow edits from maintainers permission path to authorize commits to repositories that the user can read but should not be able to write.
Источники
- https://blog.gitea.com/release-of-1.26.2/
- https://github.com/go-gitea/gitea/pull/37479
- https://github.com/go-gitea/gitea/pull/37484
- https://github.com/go-gitea/gitea/releases/tag/v1.26.2
- https://github.com/go-gitea/gitea/security/advisories/GHSA-mm7c-rhg6-qr4r
- https://github.com/go-gitea/gitea/security/advisories/GHSA-mm7c-rhg6-qr4r
Найдите уязвимость раньше атакующего.
Войдите через GitHub и запустите первый аудит меньше чем за минуту. Для бесплатного тарифа банковская карта не нужна.