CVE-2026-105268
Beschrijving NL
De Gitea API routes voor issue attachments (`/api/v1/repos/{owner}/{repo}/issues/{index}/assets/{attachment_id}`) accepteerden ook attachments die horen bij reacties op de issue. Omdat de auteur van een probleem de bijlagen van het probleem kan bewerken en verwijderen, kan een gebruiker die een probleem heeft geopend bijlagen die andere gebruikers in reacties over dat probleem hadden geplaatst, hernoemen of verwijderen. De inhoud van de bijlagen kon niet worden gewijzigd.
Origineel (Engels) tonen
The Gitea API routes for issue attachments (`/api/v1/repos/{owner}/{repo}/issues/{index}/assets/{attachment_id}`) also accepted attachments that belong to comments on the issue. Because the author of an issue may edit and delete the issue's attachments, a user who opened an issue could rename or delete attachments that other users had posted in comments on that issue. The contents of the attachments could not be changed.