code.gitea.io/gitea is vulnerable to Improper Access Control
39
Low Risk
The patched version of this package includes minor security hardening fixes addressing edge cases in request handling and permission checks. The release improves validation and access control logic to prevent unintended behavior in scenarios involving user visibility and resource access, reducing the risk of information exposure or authorization inconsistencies. Additionally, fixes to request processing and input handling help mitigate potential denial-of-service conditions triggered by malformed or unexpected input. These changes collectively strengthen the robustness of the application against low-impact security issues.
You are affected if you are using a version that falls within the vulnerable range.
code.gitea.io/gitea is vulnerable to Improper Access Control in versions 0.0.1 - 1.25.4.
Upgrade the code.gitea.io/gitea library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant