CVE-2026-20904

MEDIUM6.5EPSS 0.02%

Gitea: Broken access control in OpenID visibility toggle enables cross-user visibility changes

發布日:2026/1/23修改日:2026/2/2
也稱為:GHSA-jrpc-w85r-hgqxGHSA-qqgv-v353-cv8pBIT-gitea-2026-20904GO-2026-4369

描述

Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities.

受影響套件(3)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 4.0CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
osvCVSS 3.1MEDIUM6.5CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

參考連結(10)