An issue was discovered in Gitea through 1.11.5. An attacker can trigger a deadlock by initiating a transfer of a repository's ownership from one organization to another.
The product does not properly acquire or release a lock on a resource, leading to unexpected resource state changes and behaviors.
Link | Tags |
---|---|
https://github.com/go-gitea/gitea/issues/10549 | issue tracking patch exploit third party advisory |
https://github.com/go-gitea/gitea/pull/11438 | third party advisory patch |
https://www.youtube.com/watch?v=DmVgADSVS88 | third party advisory exploit |