Gitea doesn't adequately enforce branch deletion permissions after merging a pull request.
In Gitea before 1.22.5, branch deletion permissions are not adequately enforced after merging a pull request.
1.22.5
Exploitability
AV:N
AC:H
PR:L
UI:N
Scope
S:U
Impact
C:N
I:L
A:N
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N