CVE-2019-1000002 is an Incorrect Access Control vulnerability affecting Gitea versions 1.6.2 and earlier. An authenticated attacker with write access to any repository can exploit this flaw to delete files outside of their authorized repository. This vulnerability carries a CVSS v3.0 score of 6.5 (Medium), indicating it can be exploited over the network with low complexity, resulting in high integrity impact (data deletion) without requiring user interaction. While the vulnerability is patched in Gitea 1.6.3 and 1.7.0-rc2, there is no public exploit code, active exploitation, or significant community discussion reported.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.6.2CPE matchmatch criteria | cpe:2.3:a:gitea:gitea:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Gitea Arbitrary File Delete Vulnerability
May 13, 2022Incorrect Access Control
Incorrect Access Control
Incorrect Access Control
Incorrect Access Control
Incorrect Access Control