Severe Security Issue: full read only access to git repos without authentication #2958

Closed
opened 2025-11-02 04:55:19 -06:00 by GiteaMirror · 2 comments
Owner

Originally created by @uwebartels on GitHub (Feb 22, 2019).

  • Gitea version (or commit ref): dfad569, 1.7.1
  • Git version: 2.18.1
  • Operating system: Alpine Linux v3.8.2
  • Database (use [x]):
    • PostgreSQL
    • MySQL
    • MSSQL
    • SQLite
  • Can you reproduce the bug at https://try.gitea.io:
    • Yes (provide example URL)
    • No
    • Not relevant
  • Log gist:

Description

when using an url from a pull request, I can see the content of the pull request without authentication. After that I'm able to browse through all repositories - still without authentication.
...
screenshot

Screenshots

Originally created by @uwebartels on GitHub (Feb 22, 2019). - Gitea version (or commit ref): dfad569, 1.7.1 - Git version: 2.18.1 - Operating system: Alpine Linux v3.8.2 - Database (use `[x]`): - [x] PostgreSQL - [ ] MySQL - [ ] MSSQL - [ ] SQLite - Can you reproduce the bug at https://try.gitea.io: - [ ] Yes (provide example URL) - [ ] No - [x] Not relevant - Log gist: ## Description when using an url from a pull request, I can see the content of the pull request without authentication. After that I'm able to browse through all repositories - still without authentication. ... <img width="1348" alt="screenshot" src="https://user-images.githubusercontent.com/2845222/53244417-1d46d680-36ab-11e9-9042-c523f809ddb1.png"> ## Screenshots <!-- **If this issue involves the Web Interface, please include a screenshot** -->
Author
Owner

@uwebartels commented on GitHub (Feb 22, 2019):

this seems to be the visibility flag in the repositories. sorry.

@uwebartels commented on GitHub (Feb 22, 2019): this seems to be the visibility flag in the repositories. sorry.
Author
Owner

@lunny commented on GitHub (Feb 22, 2019):

This is a public repository.

@lunny commented on GitHub (Feb 22, 2019): This is a public repository.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github-starred/gitea#2958