Summary
An authenticated account marked restricted can read the activity feed and contribution heatmap of a Limited-visibility user through GET /api/v1/users/{username}/activities/feeds and GET /api/v1/users/{username}/heatmap. The ordinary user-information endpoint and the web/RSS profile routes correctly return 404 to the same viewer.
Details
The feed and heatmap API handlers do not apply the profile-visibility check that treats a restricted viewer like an anonymous one for Limited owners.
Impact
Confidentiality only. Exposed data can include repository names, push and commit events, full commit-message content, issue and pull request events, and contribution timestamps for any Limited-visibility user with qualifying public-repository activity.
Affected versions
Gitea <= 1.27.2.
Patches
Fixed in Gitea 1.27.3 (#39004, #39039).
Workarounds
None. Upgrade to 1.27.3.
Summary
An authenticated account marked restricted can read the activity feed and contribution heatmap of a Limited-visibility user through
GET /api/v1/users/{username}/activities/feedsandGET /api/v1/users/{username}/heatmap. The ordinary user-information endpoint and the web/RSS profile routes correctly return404to the same viewer.Details
The feed and heatmap API handlers do not apply the profile-visibility check that treats a restricted viewer like an anonymous one for Limited owners.
Impact
Confidentiality only. Exposed data can include repository names, push and commit events, full commit-message content, issue and pull request events, and contribution timestamps for any Limited-visibility user with qualifying public-repository activity.
Affected versions
Gitea
<= 1.27.2.Patches
Fixed in Gitea 1.27.3 (#39004, #39039).
Workarounds
None. Upgrade to 1.27.3.