Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources
Gitea before 1.22.3 mishandles access to a private resource upon receiving an API token with scope limited to public resources.
1.22.3
Exploitability
AV:N
AC:H
PR:L
UI:N
Scope
S:C
Impact
C:L
I:L
A:N
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N