Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
02 / AFFECTED SOFTWARE
Affected packages
36 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Gitea before 1.22.2 sometimes mishandles the propagation of token scope for access control within one of its own package registries.
Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Gitea before 1.22.2 sometimes mishandles the propagation of token scope for access control within one of its own package registries.
Gitea before 1.22.2 sometimes mishandles the propagation of token scope for access control within one of its own package registries.
05 / REFERENCES
Further evidence
- https://blog.gitea.com/release-of-1.22.2/
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/68xxx/CVE-2025-68944.json
- https://github.com/go-gitea/gitea/pull/31967
- https://github.com/go-gitea/gitea/releases/tag/v1.22.2
- https://nvd.nist.gov/vuln/detail/CVE-2025-68944
- https://blog.gitea.com/release-of-1.22.2
- https://github.com/advisories/GHSA-f85h-c7m6-cfpm
- https://github.com/go-gitea/gitea