CVE-2022-38183
Gitea allowed assignment of private issues in code.gitea.io/gitea
6.5
MEDIUM
CVSS 3.1
EPSS 0.40%
Description
In Gitea before 1.16.9, it was possible for users to add existing issues to projects. Due to improper access controls, an attacker could assign any issue to any project in Gitea (there was no permission check for fetching the issue). As a result, the attacker would get access to private issue titles.
How to fix CVE-2022-38183
To remediate CVE-2022-38183, upgrade the affected package to a fixed version below.
- —upgrade to 1.16.9 or later
- —upgrade to 1.16.9 or later
- —upgrade to 1.16.9 or later
Is CVE-2022-38183 being exploited?
Low — EPSS is 0.4%, meaning exploitation activity has not been observed at scale.
Affected packages (3)
- from 0, < 1.16.9
- from 0, < 1.16.9
- from 0, < 1.16.9
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.5 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |