You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
See doc/triage.md for instructions on how to triage this report.
modules:
- module: TODO
versions:
- fixed: 1.5.1
packages:
- package: github.com/go-gitea/gitea/models
description: Gitea version prior to version 1.5.1 contains a CWE-200 vulnerability
that can result in Exposure of users private email addresses. This attack appear
to be exploitable via Watch a repository to receive email notifications. Emails
received contain the other recipients even if they have the email set as private.
This vulnerability appears to have been fixed in 1.5.1.
cves:
- CVE-2018-1000803
ghsas:
- GHSA-f5fj-7265-jxhj
The text was updated successfully, but these errors were encountered:
In GitHub Security Advisory GHSA-f5fj-7265-jxhj, there is a vulnerability in the following Go packages or modules:
Cross references:
See doc/triage.md for instructions on how to triage this report.
The text was updated successfully, but these errors were encountered: