We found results for “”
CVE-2025-68944
Good to know:
Date: December 25, 2025
Gitea before 1.22.2 sometimes mishandles the propagation of token scope for access control within one of its own package registries.
Severity Score
Related Resources (7)
Severity Score
Weakness Type (CWE)
Unintended Proxy or Intermediary ('Confused Deputy')
CWE-441Top Fix
Upgrade Version
Upgrade to version code.gitea.io/gitea - v1.22.2;https://github.com/go-gitea/gitea.git - v1.22.2
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | LOW |
| User Interaction (UI): | NONE |
| Scope (S): | CHANGED |
| Confidentiality (C): | NONE |
| Integrity (I): | LOW |
| Availability (A): | NONE |
Vulnerabilities
Projects
Contact Us


