Beveiligingsadvies

CVE-2026-20883

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-01-22 22:01:50
Laatst bijgewerkt 2026-01-23 21:54:21
Toegewezen door Gitea
CVSS-score 6.5
Status PUBLISHED

Beschrijving

Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository is revoked, they may still view issue titles and repository names through previously started stopwatches.