Lucene search

K
osvGoogleOSV:CVE-2022-38183
HistoryAug 12, 2022 - 8:15 p.m.

CVE-2022-38183

2022-08-1220:15:09
Google
osv.dev
4
gitea
access control
unauthorized users
private issue titles

AI Score

6.7

Confidence

High

EPSS

0.001

Percentile

48.8%

In Gitea before 1.16.9, it was possible for users to add existing issues to projects. Due to improper access controls, an attacker could assign any issue to any project in Gitea (there was no permission check for fetching the issue). As a result, the attacker would get access to private issue titles.

AI Score

6.7

Confidence

High

EPSS

0.001

Percentile

48.8%