Kestrel
대시보드로 돌아가기
CVE-2026-59766MEDIUM· 4.3GHSA대응게시일: 2026. 07. 21.수정일: 2026. 07. 21.

Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times`

위협 신호 · CVSS · EPSS · KEV

정기 패치· 높은 악용 신호 없음
CVSS
4.3medium

이론적 심각도 점수

EPSS

예측 데이터 없음

KEV
미등재

실측 악용 기록 없음

권장 대응 기한60일 이내CISA SSVC 기준

계획된 패치 주기 내 조치(60일 이내)

외부 노출· KEV 미등재 · 자동화 어려움 · 부분 영향 · 외부 노출

CVSS 벡터 · 메트릭

악용 경로
공격 벡터네트워크
공격 복잡도낮음
필요 권한낮음
사용자 상호작용불필요
범위불변
영향
기밀성 영향낮음
무결성 영향없음
가용성 영향없음
버전별 점수
CVSS 3.14.3MODERATE
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

상세 설명

Summary

CVE-2026-20800 fixed private-info leakage to revoked users only for the notification endpoint. Two
sibling endpoints that return data keyed on the caller's own relationship still do not re-check repo
access at output time:

  • GET /api/v1/user/starredgetStarredRepos() computes a per-repo permission but still lists every
    starred repo (no filtering), so the full repo object (full_name, private, clone_url, ssh_url)
    of a now-inaccessible private repo is returned.
  • GET /api/v1/user/timesListMyTrackedTimes() queries by UserID only and LoadAttributes brings
    in the issue (title, state), leaking private issue titles after revocation.

Steps to reproduce

Using the provided reproduction materials, as a revoked user:

  1. Control: GET /api/v1/repos/admin/starred-test404.
  2. GET /api/v1/user/starred → leaks admin/starred-test, private:true, clone_url.
  3. GET /api/v1/user/times → leaks issue.title = "SECRET: …", state.

(Runtime-confirmed on gitea/gitea:1.25.4. Oracle = planted sentinel title; no real secret exfiltrated.)

Impact

A former collaborator can enumerate private repos they starred and read private issue titles they logged
time on, indefinitely after access revocation. Metadata only (no repo content / comment bodies). Low.

Suggested remediation

  1. getStarredRepos: drop (or minimally redact) repos where permission.HasAnyUnitAccessOrPublicAccess()
    is false for the caller.
  2. ListMyTrackedTimes: filter tracked-time entries by current repo access.
  3. Optionally clear a user's stars / time entries for a private repo on revocation.

Credit

Reported as part of an incomplete-patch measurement study (responsible disclosure).

AI 심층 분석

공격 시나리오 · 재현 가능한 PoC 페이로드 · 즉시 적용 가능한 차단 패치를 한 번에 받아 보세요. 보안 운영팀이 그대로 점검·티켓팅에 쓸 수 있는 형태로 정리해 드립니다.