{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/gitea--1.22.6/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.7,"id":"CVE-2024-52292"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Gitea (\u003c 1.22.6)"],"_cs_severities":["medium"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Gitea"],"content_html":"\u003cp\u003eA security vulnerability exists in Gitea versions prior to 1.22.6, which permits a remote, unauthenticated attacker to perform information disclosure. This flaw enables unauthorized access to repository data or internal system information that should otherwise be restricted. Defenders should prioritize patching to Gitea version 1.22.6 or later to mitigate the risk of data leakage.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows unauthorized actors to access sensitive internal data, potentially leading to the exposure of proprietary source code, credentials, or metadata stored within the Gitea instance. The scope of impact affects any organization hosting Gitea instances vulnerable to this specific information disclosure flaw.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch Gitea to version 1.22.6 or later immediately.\u003c/li\u003e\n\u003cli\u003eAudit access logs for unusual patterns of unauthenticated requests targeting repository metadata or configuration endpoints.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-24T14:00:27Z","date_published":"2026-09-24T14:00:27Z","id":"https://feed.craftedsignal.io/briefs/2026-09-gitea-info-disclosure/","summary":"A vulnerability in Gitea allows a remote, unauthenticated attacker to exploit an information disclosure flaw, potentially exposing sensitive repository or system data.","title":"Information Disclosure Vulnerability in Gitea","url":"https://feed.craftedsignal.io/briefs/2026-09-gitea-info-disclosure/"}],"language":"en","title":"CraftedSignal Threat Feed - Gitea (\u003c 1.22.6)","version":"https://jsonfeed.org/version/1.1"}