Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

You can view Private Repositories's name from other users #23150

Closed
Agusten7 opened this issue Feb 25, 2023 · 0 comments · Fixed by #23155
Closed

You can view Private Repositories's name from other users #23150

Agusten7 opened this issue Feb 25, 2023 · 0 comments · Fixed by #23155
Labels
topic/security Something leaks user information or is otherwise vulnerable. Should be fixed! type/bug
Milestone

Comments

@Agusten7
Copy link

Agusten7 commented Feb 25, 2023

Description

Technically you can't see the repositories of other users but you can see the name of that repository and know that it exists.

You have to use another account and the tool 'git clone' with the URL of the repository. You can see that the private repository exists because of the response.

Maybe this could lead to something else, in a CTF, I had to know the repository's name of the other user to make my user part of that repo by injecting a XSS and then, I could grab his SSH key to log into the machine.

The machine was Extension from HackTheBox.

Gitea Version

1.20.0

Can you reproduce the bug on the Gitea demo site?

Yes

Log Gist

No response

Screenshots

paso_1
paso_2

Git Version

2.39.2

Operating System

No response

How are you running Gitea?

I runned it from https://try.gitea.io/

Database

None

@lunny lunny added the topic/security Something leaks user information or is otherwise vulnerable. Should be fixed! label Feb 25, 2023
@lunny lunny added this to the 1.18.6 milestone Feb 26, 2023
@go-gitea go-gitea locked and limited conversation to collaborators May 3, 2023
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
topic/security Something leaks user information or is otherwise vulnerable. Should be fixed! type/bug
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants