Summary
The package-registry access check grants read access to a package owned by a Limited-visibility user to any non-ghost logged-in user, without excluding restricted accounts. A restricted account can therefore enumerate and download the entire package registry (for example Docker, npm, PyPI) of any Limited-visibility user.
Details
The user-owner branch of determineAccessMode omits the restricted-user check that the organization-owner branch and the repository permission model apply.
Impact
Authorization boundary / confidentiality. A restricted account can read package content of Limited-visibility users that it should not be able to see.
Affected versions
Gitea <= 1.27.2.
Patches
Fixed in Gitea 1.27.3 (#39043, #39058).
Workarounds
None. Upgrade to 1.27.3.
Summary
The package-registry access check grants read access to a package owned by a Limited-visibility user to any non-ghost logged-in user, without excluding restricted accounts. A restricted account can therefore enumerate and download the entire package registry (for example Docker, npm, PyPI) of any Limited-visibility user.
Details
The user-owner branch of
determineAccessModeomits the restricted-user check that the organization-owner branch and the repository permission model apply.Impact
Authorization boundary / confidentiality. A restricted account can read package content of Limited-visibility users that it should not be able to see.
Affected versions
Gitea
<= 1.27.2.Patches
Fixed in Gitea 1.27.3 (#39043, #39058).
Workarounds
None. Upgrade to 1.27.3.