code.gitea.io/gitea is vulnerable to Improper Access Control
68
Medium Risk
Affected versions of this package allow an attacker to bypass Git LFS authorization or exploit symlinks to access files outside their container or repository path. The patch enforces correct authorization for LFS requests and blocks symlink misresolution that could lead to unintended file access.
You are affected if you are using a version that falls within the vulnerable range.
code.gitea.io/gitea is vulnerable to Improper Access Control in versions 1.22.0 - 1.24.6.
Upgrade the code.gitea.io/gitea library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant