Gitea: Public-only API token restriction is not enforced on team API routes
위협 신호 · CVSS · EPSS · KEV
이론적 심각도 점수
예측 데이터 없음
실측 악용 기록 없음
계획된 패치 주기 내 조치(60일 이내)
CVSS 벡터 · 메트릭
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N상세 설명
Summary
Gitea's /api/v1/teams/{id} API routes do not correctly enforce the public-only access token restriction.
A public-only token is intended to limit API access to public repositories and public organizations. However, several team API routes continue to return private team repository metadata and private team activity feed entries when called with a public-only token.
Details
The /api/v1/teams/{teamid} route group uses:
1orgAssignment(false, true)This loads ctx.Org.Team, but does not load ctx.Org.Organization.
The checkTokenPublicOnly middleware checks organization visibility through ctx.Org.Organization. When ctx.Org.Organization is nil, the organization visibility check silently passes.
In addition, the team repository handlers return repositories without applying repository-level public-only filtering:
1repo_model.GetTeamRepositories(...) 2convert.ToRepo(...)They do not call:
1ctx.TokenCanAccessRepo(repo)The team activity feed handler also sets:
1IncludePrivate: truebut does not apply:
1opts.ApplyPublicOnly(ctx.PublicOnly)PoC
Vulnerability is verified on latest gitea release (1.26.2) and nightly build.
Frist, create a public-only organization-scoped token for a user who is a member of a team in a private org with private repositories:
Use the returned token to request team repositories:
<img width="1728" height="190" alt="image" src="https://github.com/user-attachments/assets/0f15878f-5806-431d-958c-ffb39bf7c1e9" />Expected result: Private repositories should be hidden or rejected for a public-only token.
Actual result: Private team repository metadata is returned.
The team activity feed endpoint can be tested similarly:
<img width="1728" height="237" alt="image" src="https://github.com/user-attachments/assets/280a5ddf-ad14-4769-86a8-1fdad858287c" />Impact
A public-only token can access private team resources that should be hidden from that token.
AI 심층 분석
공격 시나리오 · 재현 가능한 PoC 페이로드 · 즉시 적용 가능한 차단 패치를 한 번에 받아 보세요. 보안 운영팀이 그대로 점검·티켓팅에 쓸 수 있는 형태로 정리해 드립니다.