5.3
CVE-2025-68938
- EPSS 0.35%
- Veröffentlicht 26.12.2025 01:19:10
- Zuletzt bearbeitet 02.01.2026 19:36:14
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Gitea before 1.25.2 mishandles authorization for deletion of releases.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.35% | 0.266 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
|
| cve@mitre.org | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
|
CWE-863 Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
https://blog.gitea.com/release-of-1.25.2/
https://github.com/go-gitea/gitea/releases/tag/v1.25.2
https://github.com/go-gitea/gitea/pull/36002/commits/d4262131b39899d9e9ee5caa2635c810d476e43f#diff-8962bac89952027d50fa51f31f59d65bedb4c02bde0265eced5cf256cbed306d