Bug 2425461 (CVE-2025-68940)

Summary: CVE-2025-68940 gitea: Gitea: Unauthorized branch deletion due to inadequate permission enforcement
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedKeywords: Security
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in Gitea, a self-hosted Git service. After a pull request is merged, the system inadequately enforces branch deletion permissions. This allows an attacker with low privileges to delete branches without proper authorization, potentially leading to unauthorized changes to the repository's history and integrity.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2025-12-26 03:02:05 UTC
In Gitea before 1.22.5, branch deletion permissions are not adequately enforced after merging a pull request.