CVE-2018-1000803 is a CWE-200 vulnerability in Gitea versions prior to 1.5.1, allowing the exposure of users' private email addresses. This medium-severity vulnerability (CVSS 5.3) can be exploited by watching a repository, as email notifications inadvertently reveal other recipients' private email addresses. While the attack vector is network-based and low complexity, the impact is limited to confidentiality. There is no evidence of active exploitation, public exploit code, or significant community discussion, suggesting a low current threat level.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.5.1CPE matchmatch criteria | cpe:2.3:a:gitea:gitea:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Gitea Exposes Private Email Addresses
Feb 15, 2022Exposure of CWE-200 to users with access to specific repositories
Exposure of CWE-200 to users with access to specific repositories
Exposure of CWE-200 to users with access to specific repositories
Exposure of CWE-200 to users with access to specific repositories
Exposure of CWE-200 to users with access to specific repositories